计算机科学
随机预言
认证密钥交换
计算机安全
稳健性(进化)
认证(法律)
方案(数学)
计算机网络
密钥交换
熵(时间箭头)
重放攻击
生物识别
钥匙(锁)
会话密钥
报文认证码
集合(抽象数据类型)
块(置换群论)
密码学
密钥生成
计算机安全模型
前向保密
相互认证
会话(web分析)
公钥密码术
封面(代数)
安全性分析
作者
Mingming Jiang,Shengli Liu,Shuai Han
标识
DOI:10.1109/tdsc.2025.3603498
摘要
With a two-factor Authenticated Key Exchange (AKE) scheme, a client can use two authentication factors to help him/her set up a shared session key with a server. Taking biometric features as one factor makes the two-factor AKE not only have double-insurance security but also enjoy convenience. We design a framework of constructing a biometric-based two-factor AKE scheme $\textsf {AKE}_{\textsf {2FA}}$ from an IND-CPA secure KEM and a one-way CCA secure KEM. The resulting $\textsf {AKE}_{\textsf {2FA}}$ construction has three rounds and achieves both explicit authentication and perfect forward security in the Random Oracle (RO) model. Compared with other biometric-based two-factor AKE schemes, our $\textsf {AKE}_{\textsf {2FA}}$ supports better security since our security notions cover database leakage, robustness of two factors and KCI attacks. By plugging in Kyber in the building block of KEM, we immediately obtain a three-round Kyber-based $\textsf {AKE}_{\textsf {2FA}}$ scheme based on the module-LWE assumption. Our Kyber-based $\textsf {AKE}_{\textsf {2FA}}$ is very efficient ( $27.25\times \sim 98480\times$ faster than existing biometric-based two-factor AKE schemes) and has an acceptable communication cost of several KBs. Besides, it has no requirement for the entropy rate of the biometric source. These features suggest our scheme is practical and easy to be deployed.
科研通智能强力驱动
Strongly Powered by AbleSci AI