
计 算 机 研 究 与 发 展
DOI
:
10.7544∕issn1000G1239.2020.20200472
JournalofCom
p
uterResearchandDevelo
p
ment 57
(
10
):
2158 2176
,
2020
收稿日期
:
2020
-
06
-
12
;
修回日期
:
2020
-
07
-
30
基金项目
:
国家自然科学基金项目
(
61662083
)
Thisworkwassu
pp
ortedb
y
theNationalNaturalScienceFoundationofChina
(
61662083
)
后量子前向安全的可组合认证密钥交换方案
陈
明
(
宜春学院数学与计算机科学学院
江西宜春
336000
)
(
chenmin
g
9824@ali
y
un.com
)
ACom
p
osableAuthenticationKe
y
Exchan
g
eSchemewithPostG
Q
uantumForward
Secrec
y
Chen Min
g
(
Colle
g
eo
f
MathematicsandCom
p
uterScience
,
YichunUniversit
y
,
Yichun
,
Jian
g
xi
336000
)
Abstract Asthe
p
ostG
q
uantumeraa
pp
roaches
,
anewsecurit
y
re
q
uirementinnetworkcommunicaG
tionsisforwardsecurit
y
a
g
ainst
q
uantumcom
p
utin
g
attacks.However
,
the
p
ostG
q
uantum
p
ublicke
y
infrastructurehasnotbeenestablished
,
anditisim
p
erativetoconstructah
y
bridcr
yp
tos
y
stemthat
consistsoftraditional
p
ublicke
y
cr
yp
tos
y
stemsand
p
ostG
q
uantum ke
y
exchan
g
e
p
rotocols.Aimedat
thisneed
,
a
g
enericand combinableauthentication ke
y
exchan
g
escheme
,
named GCGAKE
,
is
p
ro
p
osed.TheGCGAKE
p
rotocolisacombinationoftwoci
p
hersuites
,
whicharesi
g
ncr
yp
tionscheme
and DiffieGHellman ke
y
exchan
g
eGlike
(
DHKEGlike
)
p
rotocol
,
res
p
ectivel
y
.In GCGAKE
,
mutual
authenticationcanberealizedb
y
usin
g
thesi
g
ncr
yp
tionschemetosi
g
ncr
yp
tthetem
p
orar
yp
ublicke
y
inDHKEGlike
,
andsessionke
y
establishmentreliesontheDHKEGlike
p
rotocol.Thesi
g
ncr
yp
tions
withstron
g
unfor
g
eabilit
y
ensurethatthe GCGAKEschemeachieves
p
erfectforwardsecurit
y
.An
instanceofthe GCGAKEis
p
ro
p
osed.Itcombinesa
p
ostG
q
uantum DHKEGlike
p
rotocol with an
identit
y
Gbased si
g
ncr
yp
tion scheme thatis
p
ut forward in this
p
a
p
er based on elli
p
tic curve
cr
yp
to
g
ra
p
h
y
.Theidentit
y
Gbasedsi
g
ncr
yp
tionschemeis
p
rovedtoachieveindistin
g
uishabilit
y
a
g
ainst
chosenci
p
hertextattacks
(
INDGCCA
)
andstron
g
existentiall
y
unfor
g
eableunderada
p
tivechosen
messa
g
esattacks
(
SEUFGCMA
)
.Furthermore
,
asecurit
y
model
,
wAKEGPFS
,
whichcansimulate
p
erfectforwardsecurit
y
,
isdefined.Underthe wAKEGPFS model
,
thesecurit
y
ofthe GCGAKE
schemeisreducedtosolvin
g
DDHGlike
(
decisionDiffieGHellmanGlike
)
p
roblems
,
aswellascrackin
g
thesecurit
y
ofidentit
y
Gbasedsi
g
ncr
yp
tionscheme.Theanal
y
sisshowsthatthe GCGAKEscheme
instanceachieves
p
erfectforwardsecurit
y
,
anditscom
p
utationandcommunicationoverheadsare
relativel
y
low.Meanwhile
,
theDHKEGlike
p
rotocolfromtherin
g
learnin
g
witherrors
p
roblem
(
Rin
g
G
LWE
)
p
rovidesforwardsecrec
y
a
g
ainstfuture
q
uantumattackers.
Ke
y
words authentication ke
y
exchan
g
e
;
DiffieGHellman ke
y
exchan
g
eGlike
;
si
g
ncr
yp
tion
;
rin
g
learnin
g
witherrors
p
roblem
;
p
erfectforwardsecrec
y
摘
要
随着后量子时代的逼近
,
网络通信安全要求会话密钥 具有针 对量子 计算攻 击的前 向安全 性
,
而
后量子的公钥基础设施尚未建立
,
采用现有公钥密钥系统与后量子密钥交换相结合的混合密码系统势在
评论