Once the shared secret key is established, three parties can use it for secure communication using symmetric-key encryption AES (128, 192, 256) algorithms or other cryptographic primitives. Although there are few third-party post-quantum authentication and key agreement protocols exist, but the recent studies in this article show that they are not anonymous or cannot provide forward secrecy. Most of the existing protocols enable adversaries to trace the source of messages. Many of third-party AKA schemes based on conventional public-key cryptosystems are vulnerable to quantum computers. Therefore, this paper contains a forward secure three-party post-quantum authenticated key establishment protocol for mobile devices. The proposed three-party key exchange protocol establishes an authenticated shared key that can be periodically refreshed to maintain forward secrecy. This protocol enables two parties to establish a shared session key even in the presence of quantum adversaries and enables them to communicate confidentially and securely over insecure networks. The protocol is anonymous as both the parties communicate using masked dynamic identities. A contrast study consisting of performance and security assessment is presented, which illustrates the suggested design is more applicable.
The three party authenticated key agreement protocol assists two parties in affirming one another and agreeing on a shared session key with the assistance of a trusted server. Chaos-based cryptography has seen considerable progress due to the sound characteristics of chaotic systems. Nowadays, many researchers are actively working in this direction and have proposed various three party authenticated key agreement protocols based on chaotic maps. In this paper, we analysed the Zheng et al. ’s scheme (IEEE Access 8:66150–66162, 2020, https://doi.org/10.1109/ACCESS.2020.2979251 ) and found that it is vulnerable to various attacks like verification table theft attack, impersonation attacks and also it does not provide anonymity to users. Zheng et al.’s scheme also has flaw in registration phase and uses timestamps for key freshness. In this article, we proposed a three party chaotic based authenticated key agreement protocol which is secured against aforementioned attacks. Authors are also compared the proposed scheme with other comparable and existing schemes in terms of security features, computation cost, and communication cost. The comparison analysis shows that the proposed scheme has more security features at a lower cost in computing and communication. We have also demonstrated the security of the proposed protocol within the framework of the random oracle model.
A three party authenticated key agreement protocol (3PAKA) enables two entities to establish a session key with the assistance of a dedicated server via an insecure channel. Recently, Islam et al. (J Inf Secur Appl 6363:103026, 2021) proposed a post-quantum secure 3PAKA scheme based on Ring-LWE and proved their protocol could fend off several typical security threats. Later, Rewal et al. (J Inf Secur Appl 75:103505, 2023) pointed out that their scheme is susceptible to password guessing attacks. However, we have found that Islam et al. protocol is not only insecure against password guessing attacks but also lacks user privacy and is susceptible to impersonation attacks. We also find that Rewal et al. scheme does not provide anonymity to users and uses time stamps for key freshness, which might cause a clock synchronization problem. With that, there is a flaw in the password update phase of Rewal’s scheme. We have proposed a 3PAKA protocol to overcome the vulnerabilities in the protocols mentioned above. We demonstrate that the new scheme strengthens security and mitigates all the existing defects of Islam et al. and Rawel et al. protocols. With this, the security comparison and performance analysis show that the proposed scheme offers a more effective solution than the existing schemes.
A three-party authenticated key exchange protocol enables two entities to agree on a session key with the help of a dedicated server over a public channel. Shor’s algorithm is a big threat to existing authenticated key exchange protocols. Lattice based cryptography plays a very important role in designing authentication and key agreements secure against the threat of quantum attacks. However, it is not an easy job to design quantum resistant password based three party protocols due to the high demand for security requirements and the limited resources nature of mobile devices. In this article, we have proposed a new post quantum three party key exchange based on ring learning with errors assumption. This protocol is motivated by Islam et al.’s authenticated key exchange protocol. Their protocol is not secure against stolen smartcard attacks, or password guessing attacks, and can’t provide user anonymity. Anonymous communication is a big requirement for practical applications like e-healthcare services/smart vehicular communication. This paper also contains the performance analysis of the proposed protocol along with other relevant protocols.
A three-party authenticated key exchange protocol enables two entities to agree on a session key with the help of a dedicated server through an insecure channel. Lattice based cryptography plays a very important role in authentication and key exchanges that protects against the threat of quantum attacks. However, it is not easy to design quantum resistant password based three-party protocol due to the high demand for security requirements and the limited resources nature of mobile devices. In this article, we have proposed a new post quantum three party key exchange based on a variant of lattice assumption, the ring learning errors. The protocol ensures security against impersonation attack, stolen smartcard attack, password guessing attack, and other existing attacks. In authentication phase, the protocol have used lattice based cryptography that plays a very important role in authentication and key exchanges that protects against the threat of quantum attacks. The proposed protocol ensures both securities against quantum attacks and efficiency due to simple algebraic operations that are polynomial addition and multiplications.
Recently, Yulei Chen and Jianhua Chen (An enchanced dynamic authentication scheme for mobile satellite communication systems. Int J Satell Commun Netw. 2020; 39(3): 250-262) presented an enhanced dynamic authentication scheme for mobile satellite communication systems in 2020. The authors found that there is a flaw in the authentication phase of the scheme proposed by Yulei Chen and Jianhua Chen's scheme. Due to this flaw, user is unable to authenticate to NCC (network control center) and also fails to establish the session key with NCC. In this paper, the authors improved the Yulei Chen and Jianhua Chen's scheme. In the proposed scheme, it is shown that user is able to authenticate to NCC (network control center) and also establish the session key with NCC. The authors also demonstrate that the computation cost and communication cost are also decreased.
The primary objective of postquantum cryptography (also known as quantum‐resistant cryptography) is to develop the cryptographic systems that need to be robust against both quantum and classical computers, and can also interoperate with the existing communications protocols and networks. In an Internet of Things (IoT) environment, the communicated messages contain sensitive information that are transmitted over an open channel, where message integrity and data privacy become challenging tasks. Although several traditional cryptographic security protocols can be applied for IoT security and data privacy, such as authentication, access control, key agreement, and digital signature, but they are not resilient against quantum attacks. To overcome these issues, in this article, we first present an advanced and efficient construction of postquantum lattice‐based signcryption scheme, and then apply the constructed lattice‐based signcryption in IoT applications, where data sensed by the deployed IoT smart devices is securely stored at the cloud, via the gateway nodes (aggregators). The data stored at the cloud servers cannot be even modified by them due to the involved signatures generated by the aggregators. The formal security analysis shows the robustness of our designed lattice‐based signcryption scheme. Other detailed information security analysis and a performance analysis with the traditional number‐theoretical based public key cryptosystems show the efficacy, and significantly better security and functionality features of the proposed scheme under the lattice‐based postquantum context.
SummarySatellite communication is one of the essential communication mechanisms that can be used for significant distance and under circumstances where the other communication mechanisms cannot work. Therefore, the security of this communication method is highly needed. Because in this era where information plays an important role, information security becomes the first priority for everyone. When we talk about information security, the key exchange and authentication are two key factors of information security. Whitfield Diffie and Martin Hellman1 proposed the first key exchange protocol. In the last two or three decades, various authentication schemes have been proposed to create a secure network that mainly depends on classical number–theoretical hard assumptions (factorization or discrete logarithm), but due to the Shor's2 algorithm, above‐mentioned scheme is no longer secure because any discrete logarithm or factorization problems can be solved by Shor's algorithm in polynomial time if the quantum computer becomes the reality soon. As far as our knowledge goes, there is no authentication protocol for satellite communication, which is secure against quantum computer attacks. Therefore, in this paper, we first proposed authentication protocol for satellite communication based on ring learning with error which is secure against quantum attacks.
Recently, many authentication schemes were proposed by researchers in the satellite communication environment. Unfortunately, several types of security flaws occur in relative works (Qi et al., 2019; Xu, 2019; Liu et al., 2017; Altaf et al., 2020), such as off-line guessing attacks, smart card stolen attacks and replay attacks. In this paper, we proposed a secure authentication technique based on chaotic maps to solve these drawbacks. To establish the security of the proposed scheme, we employ formal proof under the random oracle model. In addition, an informal study with various security properties is provided to augment the security characteristics. Furthermore, we compare our protocol to several current schemes and demonstrate that our plan meets the security criteria while being cost-effective. As a result, it is more suited to the satellite communication environment.
Mobile communication is very important for an individual users, enterprisers, industries, businesses, and organizations. Since the nodes communicate through a public channel, security, and privacy become essential component for mobile communication. Both key exchange and authentication are two important security attributes to establish secure communication between two parties. In the past few years, various post‐quantum secure authentication protocols have been designed, but we have found that either some of the protocols are vulnerable to stolen smart card attack, invalid login, or signal leakage attack. In this article, we have discussed how the protocol Dharminder et al (Dharminder D, Chandran KP. J Ambient Intell Humaniz Comput. 2020; 11:4089‐4100.) is vulnerable to modified version of signal leakage attack, and sometimes called improved signal leakage attack. We have also suggested a remedy over the current existing protocol suffering from signal leakage attacks. The proposed protocol is secure against quantum attacks. We have proved the security of the proposed protocol under ring learning with errors assumption. The proposed authentication and key agreement needs only two messages exchange. We have also found the proposed is efficient in terms of computation with respect to relevant protocols.
A vehicular ad hoc network possesses highly advanced functioning in the intelligent transportation system. This system helps moving nodes equipped with advanced smart devices, to establish reliable communication with vehicles or usable roadside units (RSUs). It has been ascertained that the privacy of the user is essential in vehicular communication to share resources among both unknown vehicles and unknown RSUs. There are some privacy‐preserving authentication schemes based on number‐theoretic assumptions, but they do not support security against quantum computers due to Shor's algorithm. Moreover, these schemes have disfavor with repeated authentication of the earlier transmitted message and being unsuccessful to search messages no longer valid during batch verification. To resolve most of the existing issues, this article brings something new to an environment, that is, edge‐computing construction into the message‐verification procedure of the system. In the proposed design, a RSU can expeditiously verify messages from nearby legitimate vehicles and broadcast to all vehicles within its communication range, which leads to a reduction in redundant verification of messages. To ensure security against quantum attacks, we have introduced an advanced design based on the hardness of a short integer solution in some random lattice. This framework guarantees autonomous driving, regular vehicular traffic flow, and a process of revocation in the advanced quantum era.
The outbreak of coronavirus has caused widespread global havoc, and the implementation of lockdown to contain the spread of the virus has caused increased levels of online healthcare services. Upgraded network technology gives birth to a new interface “telecare medicine information systems” in short TMIS. In this system, a user from a remote area and a server located at the hospital can establish a connection to share the necessary information between them. But, it is very clear that all the information is always being transmitted over a public channel. Chaotic map possesses a dynamic structure and it plays a very important role in the construction of a secure and efficient authentication protocols, but they are generally found vulnerable to identity-guess, password-guess, impersonation, and stolen smart-card. We have analyzed (Li et al. in Fut Gen Comput Syst 840:149–159, 2018; Madhusudhan and Nayak Chaitanya in A robust authentication scheme for telecare medical information systems, 2008; Zhang et al in Privacy protection for telecare medicine information systems using a chaotic map-based three-factor authenticated key agreement scheme, 2017; Dharminder and Gupta in Pratik security analysis and application of Chebyshev Chaotic map in the authentication protocols, 2019) and found that Bergamo’s attack (IEEE Trans Circ Syst 52(7):1382–1393, 2005) cannot be resisted by the protocol. Although few of the protocols ensures efficient computations but they cannot ensure an anonymous and secure communication. Therefore, we have proposed a secure and efficient chaotic map based authentication protocol that can be used in telecare medicine information system. This protocol supports verified session keys with only two messages of exchange. Moreover, we have analysed the performance of proposed protocol with relevant protocols and it is being implemented in “Automated Validation of Internet Security Protocols and Applications” respectively.
Vehicular networking allows vehicles with sensing capabilities to carry out communication from vehicle to vehicle or with accessible roadside units. To attain effective communication in vehicular networking, we have proposed a hybrid technological solution in terms of vehicular edge computing (VEC) utilizing resources, cloud and edge server environment. The proposed architecture supports a frequent communication between a vehicle and a legitimate edge server without any trusted party communication. Both security and privacy are two key challenges in edge based vehicular communications due to the adoption of a real-time environment that is required to respond to hundreds of moving vehicles. This paper presents an edge computing-based framework for vehicular communication to ensure security, message integrity, and privacy. The presented framework attains all security attributes in the presence of active as well as passive adversaries. The formal security proof ensures its correctness and robustness. The analysis indicates that it is secure and efficient, being based on new edge computing framework as compared to general cloud computing framework.