| 摘要: |
| Kyber是一个基于格上困难问题的密钥封装机制, 2023年被美国国家标准与技术研究院宣布为第1批标准化对象. Kyber-AKE是Kyber的设计者基于Kyber构造的弱前向安全的认证密钥交换, 通过使用3个IND-CCA安全的密钥封装机制在两轮内协商会话密钥. 介绍Kyber-PFS-AKE, 这是一种新的认证密钥交换协议. Kyber-PFS-AKE只使用了3个IND-CPA安全的公钥加密, 并通过FO变换中的重加密技术处理IND-CPA安全公钥加密中的解密错误, 从而简化了后量子Kyber-AKE的设计. 严格证明Kyber-AKE协议中某些操作是冗余的, 去除这些冗余后, 协议变得更加简单和高效. 在eCK-PFS-PSK模型下证明Kyber-PFS-AKE的会话密钥不可区分性质, 以及完美的前向安全性等安全性质. 使用量子安全为165-bit的Kyber-768, PKE实现了Kyber-PFS-AKE. 实验结果表明, Kyber-PFS-AKE相比于Kyber-AKE, 发起者计算时间降低了38%, 响应者计算时间降低了30%. |
| 关键词: 公钥加密方案 Kyber 认证密钥交换 |
| DOI:10.13328/j.cnki.jos.007393 |
| 分类号:TP309 |
| 基金项目:国家重点研发计划 (2021YFB3100100) |
|
| Efficient Authenticated Key Exchange Protocol Based on Kyber Public-key Encryption |
|
MI Rui-Qi1,2, JIANG Hao-Dong3, ZHANG Zhen-Feng1,2
|
|
1.Institute of Software, Chinese Academy of Sciences, Beijing 100190, China;2.University of Chinese Academy of Sciences, Beijing 100049, China;3.Henan Key Laboratory of Network Cryptography Technology, Zhengzhou 450001, China
|
| Abstract: |
| Kyber, a key encapsulation mechanism based on lattice problems, was the first to be standardized by the National Institute of Standards and Technology (NIST) in 2023. Kyber-AKE, a weak forward-secure authenticated key exchange (AKE) protocol, was constructed by the designers of Kyber and derives session keys in two rounds using three IND-CCA secure key encapsulation mechanisms. This study introduces Kyber-PFS-AKE, a newly proposed authenticated key exchange protocol. In Kyber-PFS-AKE, only IND-CPA secure public-key encryption is utilized, and decryption errors within IND-CPA secure encryption are addressed using the re-encryption technique within the FO transformation, thus simplifying the design of post-quantum Kyber-AKE. A rigorous proof demonstrates that certain operations in the Kyber-AKE protocol are redundant. By eliminating these redundancies, the protocol achieves a simpler and more efficient design. The session key indistinguishability and perfect forward security of Kyber-PFS-AKE are formally proven within the eCK-PFS-PSK model. The proposed Kyber-PFS-AKE is implemented using Kyber-768. PKE with 165-bit quantum security. Experimental results show that compared to Kyber-AKE, the computation time for the initiator is reduced by 38%, while the computation time for the responder is reduced by 30%. |
| Key words: public-key encryption (PKE) schema Kyber authenticated key exchange (AKE) |