<p>Cryptography underpins secure communication by ensuring confidentiality, integrity, and authentication in digital systems. The Diffie-Hellman Key Exchange Protocol (DHKEP) is a cornerstone for establishing shared secret keys, enabling secure symmetric encryption over insecure channels. However, DHKEP is vulnerable to man-in-the-middle (MITM) attack and reused key attack (RKA), compromising privacy and security, particularly on resource-constrained devices. This paper proposes a novel hybrid protocol integrating DHKEP with the RSA cryptosystem to mitigate these vulnerabilities. By employing dual encryption-first using private keys, then public keys-under modular arithmetic and primitive roots, the protocol ensures robust key exchange. Compared to existing authenticated key exchange (AKE) protocols, it requires fewer rounds and security parameters, reducing computational and communication overhead. Validated using the Automated Validation of Internet Security Protocols and Applications (AVISPA) tool under the Random Oracle (RO) model, the protocol demonstrates perfect forward secrecy, key revocation, and resilience against MITM and RKA. On comparing with the existing schemes it has been found that that the proposed protocol offers superior resilience against both key interception and impersonation, achieving an average impersonation probability as low as 0.341 which results 35–45% lower than the existing works. This approach offers a scalable, efficient solution for secure key exchange in resource-constrained environments, advancing the security of continuous key agreement protocols.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

A novel approach to key exchange: dual-secured Diffie-Hellman with RSA integration

  • Shabbir Hassan,
  • Arman Rasool Faridi,
  • Ahmad Raza Shibli,
  • Santosh Kumar Srivastava

摘要

Cryptography underpins secure communication by ensuring confidentiality, integrity, and authentication in digital systems. The Diffie-Hellman Key Exchange Protocol (DHKEP) is a cornerstone for establishing shared secret keys, enabling secure symmetric encryption over insecure channels. However, DHKEP is vulnerable to man-in-the-middle (MITM) attack and reused key attack (RKA), compromising privacy and security, particularly on resource-constrained devices. This paper proposes a novel hybrid protocol integrating DHKEP with the RSA cryptosystem to mitigate these vulnerabilities. By employing dual encryption-first using private keys, then public keys-under modular arithmetic and primitive roots, the protocol ensures robust key exchange. Compared to existing authenticated key exchange (AKE) protocols, it requires fewer rounds and security parameters, reducing computational and communication overhead. Validated using the Automated Validation of Internet Security Protocols and Applications (AVISPA) tool under the Random Oracle (RO) model, the protocol demonstrates perfect forward secrecy, key revocation, and resilience against MITM and RKA. On comparing with the existing schemes it has been found that that the proposed protocol offers superior resilience against both key interception and impersonation, achieving an average impersonation probability as low as 0.341 which results 35–45% lower than the existing works. This approach offers a scalable, efficient solution for secure key exchange in resource-constrained environments, advancing the security of continuous key agreement protocols.