Privacy-Preserving Certificate-Less Authenticated Key Exchange with Key Registration Privacy
摘要
As an enhanced variant of authenticated key exchange protocol (AKE), privacy-preserving authenticated key exchange (PPAKE) protocols aim to provide both session key indistinguishability and party identity privacy. However, relying on public key infrastructure (PKI) or similar services for authentication, especially for validating certificates and other identity-binding tokens during the handshake, may have sub-optimal efficiency and open attack surfaces for privacy adversaries. Certificate-less(CL) cryptography does not rely on PKI or certificates, but few existing CL-AKE considers privacy after the key generation center (KGC) is compromised. In this paper, we propose new privacy-preserving protocols including certificate-less key registration and AKE protocol that enjoy both key indistinguishability and privacy. Our starting point is a certificate-less signature (CL-SIG) in an alternative syntax, and the CL-AKE proposal can provide enhanced privacy especially when the long-term key of the KGC has been compromised.