TY - JOUR
T1 - Simulatable certificateless two-party authenticated key agreement protocol
AU - Zhang, Lei
AU - Zhang, Futai
AU - Wu, Qianhong
AU - Domingo-Ferrer, Josep
PY - 2010/3/15
Y1 - 2010/3/15
N2 - Key agreement (KA) allows two or more users to negotiate a secret session key among them over an open network. Authenticated key agreement (AKA) is a KA protocol enhanced to prevent active attacks. AKA can be achieved using a public-key infrastructure (PKI) or identity-based cryptography. However, the former suffers from a heavy certificate management burden while the latter is subject to the so-called key escrow problem. Recently, certificateless cryptography was introduced to mitigate these limitations. In this paper, we first propose a security model for AKA protocols using certificateless cryptography. Following this model, we then propose a simulatable certificateless two-party AKA protocol. Security is proven under the standard computational Diffie-Hellman (CDH) and bilinear Diffie-Hellman (BDH) assumptions. Our protocol is efficient and practical, because it requires only one pairing operation and five multiplications by each party.
AB - Key agreement (KA) allows two or more users to negotiate a secret session key among them over an open network. Authenticated key agreement (AKA) is a KA protocol enhanced to prevent active attacks. AKA can be achieved using a public-key infrastructure (PKI) or identity-based cryptography. However, the former suffers from a heavy certificate management burden while the latter is subject to the so-called key escrow problem. Recently, certificateless cryptography was introduced to mitigate these limitations. In this paper, we first propose a security model for AKA protocols using certificateless cryptography. Following this model, we then propose a simulatable certificateless two-party AKA protocol. Security is proven under the standard computational Diffie-Hellman (CDH) and bilinear Diffie-Hellman (BDH) assumptions. Our protocol is efficient and practical, because it requires only one pairing operation and five multiplications by each party.
KW - Authenticated key agreement
KW - Certificateless cryptography
KW - Information security
KW - Protocol design
KW - Provable security
UR - https://www.scopus.com/pages/publications/73149101252
U2 - 10.1016/j.ins.2009.11.036
DO - 10.1016/j.ins.2009.11.036
M3 - 文章
AN - SCOPUS:73149101252
SN - 0020-0255
VL - 180
SP - 1020
EP - 1030
JO - Information Sciences
JF - Information Sciences
IS - 6
ER -