<p>Authentication enables keeping systems secure by allowing only authenticated entities and processes to access their protected resources such as databases, applications, networks, services, etc. Password-based security is one of the most important forms of user authentication and one of the weakest as well. Password-related violations are the main cause of safety loss. However, people continue to use it to protect their most important systems because of its easiness and popularity. This paper presents a secure and lightweight mutual authentication protocol based on passwords. To realize post-quantum cryptography, the proposed approach uses a zero-knowledge proof model. After the registration stage, the process of authentication is defined through a two-stage process, which ensures an exchange of a predefined password using linear encryption. Upon receiving an access demand from an entity, the first stage consists of generating two random numbers by the system. To hide the password, the process consists of multiplying one of them by the password’s hash and then adding the other, so that an eavesdropper can never get any information from an intercepted transmission. The entity authenticates the system by exploiting the hidden password and, in turn, hides its password in the same way using one of the sent random values by the system as proof. Finally, the system can easily authenticate this entity and use the generated value as a key session. Our approach is analyzed and evaluated based on its communication and computation costs. The obtained results prove its high-security level and performance.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

A Secure and Lightweight ZKP-based Mutual Authentication Scheme with Key Agreement

  • Ahcene Bounceur

摘要

Authentication enables keeping systems secure by allowing only authenticated entities and processes to access their protected resources such as databases, applications, networks, services, etc. Password-based security is one of the most important forms of user authentication and one of the weakest as well. Password-related violations are the main cause of safety loss. However, people continue to use it to protect their most important systems because of its easiness and popularity. This paper presents a secure and lightweight mutual authentication protocol based on passwords. To realize post-quantum cryptography, the proposed approach uses a zero-knowledge proof model. After the registration stage, the process of authentication is defined through a two-stage process, which ensures an exchange of a predefined password using linear encryption. Upon receiving an access demand from an entity, the first stage consists of generating two random numbers by the system. To hide the password, the process consists of multiplying one of them by the password’s hash and then adding the other, so that an eavesdropper can never get any information from an intercepted transmission. The entity authenticates the system by exploiting the hidden password and, in turn, hides its password in the same way using one of the sent random values by the system as proof. Finally, the system can easily authenticate this entity and use the generated value as a key session. Our approach is analyzed and evaluated based on its communication and computation costs. The obtained results prove its high-security level and performance.