A Secure and Lightweight ZKP-based Mutual Authentication Scheme with Key Agreement
摘要
Authentication enables keeping systems secure by allowing only authenticated entities and processes to access their protected resources such as databases, applications, networks, services, etc. Password-based security is one of the most important forms of user authentication and one of the weakest as well. Password-related violations are the main cause of safety loss. However, people continue to use it to protect their most important systems because of its easiness and popularity. This paper presents a secure and lightweight mutual authentication protocol based on passwords. To realize post-quantum cryptography, the proposed approach uses a zero-knowledge proof model. After the registration stage, the process of authentication is defined through a two-stage process, which ensures an exchange of a predefined password using linear encryption. Upon receiving an access demand from an entity, the first stage consists of generating two random numbers by the system. To hide the password, the process consists of multiplying one of them by the password’s hash and then adding the other, so that an eavesdropper can never get any information from an intercepted transmission. The entity authenticates the system by exploiting the hidden password and, in turn, hides its password in the same way using one of the sent random values by the system as proof. Finally, the system can easily authenticate this entity and use the generated value as a key session. Our approach is analyzed and evaluated based on its communication and computation costs. The obtained results prove its high-security level and performance.