In the post-quantum era,the password-based authentication key exchange(PAKE)protocol on lattice has the characteristics of convenience and high efficiency,however these protocols cannot resist online dictionary attack...In the post-quantum era,the password-based authentication key exchange(PAKE)protocol on lattice has the characteristics of convenience and high efficiency,however these protocols cannot resist online dictionary attack that is a common method used by attackers.A lattice-based two-factor(biometric and password)authentication key exchange(TFAKE)protocol based on key consensus(KC)is proposed.The protocol encapsulates the hash value of biometric information and password through a splittable encryption method,and compares the decapsulated information with the server's stored value to achieve the dual identity authentication.Then the protocol utilizes the asymmetric hash structure to simplify the calculation steps,which increases the calculation efficiency.Moreover,KC algorithm is employed in reducing data transmission overhead.Compared with the current PAKE protocol,the proposed protocol has the characteristics of hybrid authentication and resisting online dictionary attack.And it reduces the number of communication rounds and improves the efficiency and the security of protocol application.展开更多
基金This work was supported by the National Natural Science Foundation of China(61802117)Support Plan of Scientific and Technological Innovation Team in Universities of Henan Province(20IRTSTHN013)+2 种基金Henan Key Laboratory of Network Cryptography Technology(LNCT2019-A04)Scientific and Technological Project of Henan Province(192102210280)Key Scientific Research Projects of Universities in Henan Province(19A520025).
文摘In the post-quantum era,the password-based authentication key exchange(PAKE)protocol on lattice has the characteristics of convenience and high efficiency,however these protocols cannot resist online dictionary attack that is a common method used by attackers.A lattice-based two-factor(biometric and password)authentication key exchange(TFAKE)protocol based on key consensus(KC)is proposed.The protocol encapsulates the hash value of biometric information and password through a splittable encryption method,and compares the decapsulated information with the server's stored value to achieve the dual identity authentication.Then the protocol utilizes the asymmetric hash structure to simplify the calculation steps,which increases the calculation efficiency.Moreover,KC algorithm is employed in reducing data transmission overhead.Compared with the current PAKE protocol,the proposed protocol has the characteristics of hybrid authentication and resisting online dictionary attack.And it reduces the number of communication rounds and improves the efficiency and the security of protocol application.