arrow
返回

Quantum2FA: Efficient Quantum-Resistant Two-Factor Authentication Scheme for Mobile Devices

delete2023-01-01
delete106
PRE
AI
Q
Qingxuan Wang
D
Ding Wang *
C
Cheng Chi
D
Debiao He
DOI:10.1109/TDSC.2021.3129512delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
Smart-card based password authentication has been the most widely used two-factor authentication (2FA) mechanism for security-critical applications (e.g., e-Health, smart grid and e-Commerce) in the past decades, and it is likely to hold its status in the foreseeable future. Hundreds of this type of 2FA schemes have been proposed, yet to our knowledge, most of them are built on the intractability of conventional hard problems (e.g., discrete logarithm problems and integer factoring problems) which are no longer hard in the quantum era. With the recent advancements in quantum computing, the design of secure and efficient smart-card based password authentication schemes against quantum attacks is becoming increasingly urgent. However, it is not as simple as it seems, how to design such a quantum-resistant 2FA scheme is challenging due to the demanding security requirements and the resource-constrained nature of mobile devices. In this work, we take the first step towards this issue by proposing Quantum2FA, a practical quantum-resistant smart-card-based password authentication scheme that employs Alkim et al.'s lattice-based key exchange and Wang-Wang's fuzzy-verifier + honeywords technique (IEEE TDSC'18). Particularly, Quantum2FA can thwart the newly revealed key-reuse attack (ACISP'18, CT-RSA'19) against lattice-based key exchange schemes in two aspects: signal leakage attacks and key mismatch attacks. Specifically, it restricts the necessary conditions (i.e., the attacker must be the initiator of the key exchange) for an adversary to analyze the signal; It introduces honeywords to detect the key mismatches between the smart card and the server, and thus smart card loss attack can be thwarted. We formally prove the security of Quantum2FA under the random oracle model and demonstrate its efficiency through experiments on a 32 MHz 8-bit AVR Embedded Processor. Comparison results show that Quantum2FA is not only more secure but also offers better computation efficiency than the state-of-the-art conventional 2FA schemes.
Keyword:
Authentication
Security
Quantum computing
Cryptography
Smart cards
Passwords
Resistance
Two-factor authentication
quantum security
lattice-based cryptography
key-reuse
honeyword

期刊

IEEE Transactions on Dependable and Secure Computing 封面图
IEEE Transactions on Dependable and Secure Computing
IF:
7.5
论文数:
2.4K
被引数:
9.6K

机构

C
China University of Geosciences
学者数:
3.7W
论文数: 2.8W
被引数: 4.3W
G
Guilin University of Electronic Technology
学者数:
7.4K
论文数: 5.2K
被引数: 5.4K
N
nankai university
学者数:
4.8W
论文数: 3.3W
被引数: 74
学者 查看更多机构
引用论文

引用论文

Leukocyte proteases cleave von Willebrand factor at or near the ADAMTS13 cleavage site
err2009-08-20
err0
errOAAI
errThomas J. Raife; Wenjing Cao; Bonnie S. Atkinson; Bruce Bedell; Robert R. Montgomery; Steven R. Lentz; George F. Johnson; X. Long Zheng
err分享
err收藏
err分享
err收藏
Caring for each other: a rapid review of how mutual dependency is challenged by advanced illness
err2021-08-01
err0
errOAAI
errJoanne Elizabeth Parsons; Jeremy Dale; John I. MacArtney; Veronica Nanton
err分享
err收藏
err分享
err收藏
err分享
err收藏
学者 查看更多内容