{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,2,21]],"date-time":"2025-02-21T07:21:46Z","timestamp":1740122506423,"version":"3.37.3"},"reference-count":31,"publisher":"Springer Science and Business Media LLC","issue":"10","license":[{"start":{"date-parts":[[2024,7,27]],"date-time":"2024-07-27T00:00:00Z","timestamp":1722038400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2024,7,27]],"date-time":"2024-07-27T00:00:00Z","timestamp":1722038400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Des. Codes Cryptogr."],"published-print":{"date-parts":[[2024,10]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>We present Transmission optimal protocol with active security (<jats:inline-formula><jats:alternatives><jats:tex-math>$$\\textsf {TOPAS}$$<\/jats:tex-math><mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                  <mml:mi>TOPAS<\/mml:mi>\n                <\/mml:math><\/jats:alternatives><\/jats:inline-formula>), the first key agreement protocol with optimal communication complexity (message size and number of rounds) that provides security against fully active adversaries. The size of the protocol messages and the computational costs to generate them are comparable to the basic Diffie-Hellman protocol over elliptic curves (which is well-known to only provide security against passive adversaries). Session keys are indistinguishable from random keys\u2014even under reflection and key compromise impersonation attacks. What makes <jats:inline-formula><jats:alternatives><jats:tex-math>$$\\textsf {TOPAS}$$<\/jats:tex-math><mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                  <mml:mi>TOPAS<\/mml:mi>\n                <\/mml:math><\/jats:alternatives><\/jats:inline-formula>stand out is that it also features a security proof of full perfect forward secrecy (PFS), where the attacker can <jats:italic>actively<\/jats:italic> modify messages sent to or from the test-session. The proof of full PFS relies on two new extraction-based security assumptions. It is well-known that existing implicitly-authenticated 2-message protocols like <jats:inline-formula><jats:alternatives><jats:tex-math>$$\\textsf {HMQV}$$<\/jats:tex-math><mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                  <mml:mi>HMQV<\/mml:mi>\n                <\/mml:math><\/jats:alternatives><\/jats:inline-formula>cannot achieve this strong form of (full) security against active attackers (Krawczyk, Crypto\u201905). This makes <jats:inline-formula><jats:alternatives><jats:tex-math>$$\\textsf {TOPAS}$$<\/jats:tex-math><mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                  <mml:mi>TOPAS<\/mml:mi>\n                <\/mml:math><\/jats:alternatives><\/jats:inline-formula>the first key agreement protocol with full security against active attackers that works in prime-order groups while having optimal message size. We also present a variant of our protocol, <jats:inline-formula><jats:alternatives><jats:tex-math>$$\\textsf {TOPAS+}$$<\/jats:tex-math><mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                  <mml:mrow>\n                    <mml:mi>TOPAS<\/mml:mi>\n                    <mml:mo>+<\/mml:mo>\n                  <\/mml:mrow>\n                <\/mml:math><\/jats:alternatives><\/jats:inline-formula>, which, under the Strong Diffie-Hellman assumption, provides better computational efficiency in the key derivation phase. Finally, we present a third protocol termed <jats:inline-formula><jats:alternatives><jats:tex-math>$$\\textsf {FACTAS}$$<\/jats:tex-math><mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                  <mml:mi>FACTAS<\/mml:mi>\n                <\/mml:math><\/jats:alternatives><\/jats:inline-formula>(for factoring-based protocol with active security) which has the same strong security properties as <jats:inline-formula><jats:alternatives><jats:tex-math>$$\\textsf {TOPAS}$$<\/jats:tex-math><mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                  <mml:mi>TOPAS<\/mml:mi>\n                <\/mml:math><\/jats:alternatives><\/jats:inline-formula>and <jats:inline-formula><jats:alternatives><jats:tex-math>$$\\textsf {TOPAS+}$$<\/jats:tex-math><mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                  <mml:mrow>\n                    <mml:mi>TOPAS<\/mml:mi>\n                    <mml:mo>+<\/mml:mo>\n                  <\/mml:mrow>\n                <\/mml:math><\/jats:alternatives><\/jats:inline-formula>but whose security is solely based on the factoring assumption in groups of composite order (except for the proof of full PFS).<\/jats:p>","DOI":"10.1007\/s10623-024-01429-3","type":"journal-article","created":{"date-parts":[[2024,7,27]],"date-time":"2024-07-27T11:02:03Z","timestamp":1722078123000},"page":"3085-3124","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["$$\\textsf {TOPAS}$$2-pass key exchange with full perfect forward secrecy and optimal communication complexity"],"prefix":"10.1007","volume":"92","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-8698-4244","authenticated-orcid":false,"given":"Sven","family":"Sch\u00e4ge","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2024,7,27]]},"reference":[{"key":"1429_CR1","doi-asserted-by":"crossref","unstructured":"Abdalla, M., Bellare, M., Rogaway, P.: The oracle Diffie-Hellman assumptions and an analysis of DHIES. Topics in Cryptology-CT-RSA 2001: The Cryptographers\u2019 Track at RSA Conference 2001 San Francisco, CA, USA, April 8-\u201312, 2001 Proceedings. Springer, Berlin (2001).","DOI":"10.1007\/3-540-45353-9_12"},{"key":"1429_CR2","series-title":"Lecture Notes in Computer Science","first-page":"319","volume-title":"Selected Areas in Cryptography","author":"PSLM Barreto","year":"2005","unstructured":"Barreto P.S.L.M., Naehrig M.: Pairing-friendly elliptic curves of prime order. In: Preneel B., Tavares S.E. (eds.) Selected Areas in Cryptography, pp. 319\u2013331. Lecture Notes in Computer Science. Springer, New York (2005)."},{"key":"1429_CR3","doi-asserted-by":"publisher","unstructured":"Bergsma, F., Jager, T., Schwenk, J.: One-round key exchange with strong security: An efficient and generic construction in the standard model. Public-Key Cryptography\u2013PKC 2015: 18th IACR International Conference on Practice and Theory in Public-Key Cryptography, Gaithersburg, MD, USA, March 30\u2013April 1, 2015, Proceedings 18. Springer, Berlin (2015). https:\/\/doi.org\/10.1007\/978-3-662-46447-2_21","DOI":"10.1007\/978-3-662-46447-2_21"},{"key":"1429_CR4","doi-asserted-by":"crossref","unstructured":"Boneh D., Lynn B., Shacham H.: Short signatures from the Weil pairing. In: International conference on the theory and application of cryptology and information security. Berlin: Springer 17(4), pp. 297\u2013319 (2004).","DOI":"10.1007\/s00145-004-0314-9"},{"key":"1429_CR5","doi-asserted-by":"crossref","unstructured":"Boneh, D., Gentry, C., Lynn, B., Shacham, H.: Aggregate and verifiably encrypted signatures from bilinear maps. In: Advances in Cryptology\u2014EUROCRYPT 2003: International Conference on the Theory and Applications of Cryptographic Techniques, Warsaw, Poland, May 4-\u20138, 2003 Proceedings 22. Springer Berlin (2003).","DOI":"10.1007\/3-540-39200-9_26"},{"issue":"4","key":"1429_CR6","first-page":"659","volume":"24","author":"D Boneh","year":"2011","unstructured":"Boneh D., Boyen X.: J. Cryptol. Efficient selective identity-based encryption without random oracles 24(4), 659\u2013693 (2011).","journal-title":"Efficient selective identity-based encryption without random oracles"},{"key":"1429_CR7","doi-asserted-by":"publisher","unstructured":"Boyd, C., Nieto, J.G.: On forward secrecy in one-round key exchange. In: Chen, L. (ed.) Cryptography and Coding-13th IMA International Conference, IMACC 2011, Oxford, UK, December 12\u201315, 2011. Proceedings. Lecture Notes in Computer Science, vol. 7089, pp. 451\u2013468. Springer, New York (2011). https:\/\/doi.org\/10.1007\/978-3-642-25516-8_27 . https:\/\/doi.org\/10.1007\/978-3-642-25516-8_27","DOI":"10.1007\/978-3-642-25516-8_27"},{"key":"1429_CR8","doi-asserted-by":"crossref","unstructured":"Boyen, X.: The uber-assumption family (invited talk). In: 2nd International Conference on Pairing-based Cryptography (PAIRING 2008), volume 5209 of Lecture Notes in Computer Science, pp. 39\u201356(2008).","DOI":"10.1007\/978-3-540-85538-5_3"},{"key":"1429_CR9","doi-asserted-by":"crossref","unstructured":"Canetti, R., Krawczyk, H.: Analysis of key-exchange protocols and their use for building secure channels. In: International conference on the theory and applications of cryptographic techniques. Berlin: pp. 453\u2013474. (2001).","DOI":"10.1007\/3-540-44987-6_28"},{"key":"1429_CR10","first-page":"470","volume":"8","author":"D Cash","year":"2008","unstructured":"Cash D., Kiltz E., Shoup V.: The twin Diffie-Hellman problem and applications. J. Cryptol. 8, 470\u2013504 (2008).","journal-title":"J. Cryptol."},{"key":"1429_CR11","doi-asserted-by":"publisher","first-page":"15","DOI":"10.1007\/978-3-319-08344-5_18","volume":"15","author":"Y Chen","year":"2014","unstructured":"Chen Y., Huang Q., Zhang Z.: Sakai\u2013Ohgishi\u2013Kasahara identity-based non-interactive key exchange revisited and more. Int. J. Inform. Secur. 15, 15\u201333 (2014). https:\/\/doi.org\/10.1007\/978-3-319-08344-5_18.","journal-title":"Int. J. Inform. Secur."},{"key":"1429_CR12","doi-asserted-by":"crossref","unstructured":"Cremers, C.J.F., Feltz, M.: Beyond eCK: Perfect forward secrecy under actor compromise and ephemeral-key reveal. Computer Security\u2013ESORICS 2012: 17th European Symposium on Research in Computer Security, Pisa, Italy, September 10\u201312, 2012. Proceedings 17. Springer Berlin (2012).","DOI":"10.1007\/978-3-642-33167-1_42"},{"key":"1429_CR13","unstructured":"Damg\u00e5rd, I.: Towards practical public key systems secure against chosen ciphertext attacks. Advances in Cryptology\u2014CRYPTO\u201991: Proceedings 11. Springer, Berlin (1992)."},{"key":"1429_CR14","doi-asserted-by":"crossref","unstructured":"Di Raimondo, M., Gennaro, R., Krawczyk, H.: Deniable authentication and key exchange, In: Proceedings of the 13th ACM conference on Computer and communications security. pp. 400\u2013409 (2006).","DOI":"10.1145\/1180405.1180454"},{"issue":"6","key":"1429_CR15","doi-asserted-by":"publisher","first-page":"644","DOI":"10.1109\/TIT.1976.1055638","volume":"22","author":"W Diffie","year":"1976","unstructured":"Diffie W., Hellman M.E.: New directions in cryptography. IEEE Trans. Inform. Theory IT 22(6), 644\u2013654 (1976).","journal-title":"IEEE Trans. Inform. Theory IT"},{"key":"1429_CR16","unstructured":"Feltz, M., Cremers, C.: On the limits of authenticated key exchange security with an application to bad randomness. IACR Cryptology ePrint Archive, 369 (2014)."},{"key":"1429_CR17","doi-asserted-by":"crossref","unstructured":"Fiore, D., Gennaro, R.: Making the Diffie\u2013Hellman protocol identity-based. Topics in Cryptology-CT-RSA 2010: The Cryptographers\u2019 Track at the RSA Conference 2010, San Francisco, CA, USA, March 1\u20135, 2010. Proceedings (2010).","DOI":"10.1007\/978-3-642-11925-5_12"},{"key":"1429_CR18","doi-asserted-by":"publisher","unstructured":"Fischlin, M., Fleischhacker, N.: Limitations of the meta-reduction technique: The case of schnorr signatures. Annual International Conference on the Theory and Applications of Cryptographic Techniques. Berlin, Heidelberg, pp. 444\u2013460. (2013). https:\/\/doi.org\/10.1007\/978-3-642-38348-9_27","DOI":"10.1007\/978-3-642-38348-9_27"},{"issue":"16","key":"1429_CR19","doi-asserted-by":"publisher","first-page":"3113","DOI":"10.1016\/j.dam.2007.12.010","volume":"156","author":"SD Galbraith","year":"2008","unstructured":"Galbraith S.D., Paterson K.G., Smart N.P.: Pairings for cryptographers. Discret, Appl. Math. 156(16), 3113\u20133121 (2008).","journal-title":"Discret, Appl. Math."},{"key":"1429_CR20","doi-asserted-by":"crossref","unstructured":"Gennaro, R., Krawczyk, H., Rabin, T.: Okamoto\u2013Tanaka revisited: Fully authenticated Diffie\u2013Hellman with minimal overhead. Applied Cryptography and Network Security: 8th International Conference, ACNS 2010, Beijing, China, June 22\u201325. Proceedings 8. Springer Berlin (2010).","DOI":"10.1007\/978-3-642-13708-2_19"},{"issue":"2","key":"1429_CR21","doi-asserted-by":"publisher","first-page":"71","DOI":"10.1007\/s00145-002-0038-7","volume":"16","author":"O Goldreich","year":"2003","unstructured":"Goldreich O., Rosen V.: On the security of modular exponentiation with application to the construction of pseudorandom generators. Cryptology 16(2), 71\u201393 (2003).","journal-title":"Cryptology"},{"key":"1429_CR22","doi-asserted-by":"crossref","unstructured":"Hofheinz, D., Kiltz, E.: The group of signed quadratic residues and applications. Annual International Cryptology Conference. Berlin, Heidelberg, pp. 637\u2013653. (2009).","DOI":"10.1007\/978-3-642-03356-8_37"},{"key":"1429_CR23","doi-asserted-by":"publisher","unstructured":"Krawczyk, H.: SKEME: a versatile secure key exchange mechanism for internet. In: 1996 Symposium on Network and Distributed System Security, (S)NDSS \u201996, San Diego, CA, February 22\u201323, 1996, pp. 114\u2013127 (1996).https:\/\/doi.org\/10.1109\/NDSS.1996.492418. http:\/\/doi.ieeecomputersociety.org\/10.1109\/NDSS.1996.492418","DOI":"10.1109\/NDSS.1996.492418"},{"key":"1429_CR24","first-page":"546","volume-title":"HMQV: A High-performance Secure Diffie\u2013Hellman Protocol","author":"H Krawczyk","year":"2005","unstructured":"Krawczyk H.: HMQV: A High-performance Secure Diffie\u2013Hellman Protocol, pp. 546\u2013566. Springer, Berlin (2005)."},{"issue":"2","key":"1429_CR25","doi-asserted-by":"publisher","first-page":"119","DOI":"10.1023\/A:1022595222606","volume":"28","author":"L Law","year":"2003","unstructured":"Law L., Menezes A., Qu M., Solinas J.A., Vanstone S.A.: An efficient protocol for authenticated key agreement. Des. Codes Cryptogr. 28(2), 119\u2013134 (2003).","journal-title":"Des. Codes Cryptogr."},{"issue":"4","key":"1429_CR26","doi-asserted-by":"publisher","first-page":"481","DOI":"10.1109\/49.17711","volume":"7","author":"E Okamoto","year":"1989","unstructured":"Okamoto E., Tanaka K.: Key distribution system based on identification information. IEEE J. Select. Areas Commun. 7(4), 481\u2013485 (1989). https:\/\/doi.org\/10.1109\/49.17711.","journal-title":"IEEE J. Select. Areas Commun."},{"issue":"5","key":"1429_CR27","doi-asserted-by":"publisher","first-page":"634","DOI":"10.1016\/j.comnet.2008.11.001","volume":"53","author":"K Ratnam","year":"2009","unstructured":"Ratnam K., Gurusamy M., Zhou L.: Differentiated survivability with improved fairness in ip\/mpls-over-wdm optical networks. Comput. Netw. 53(5), 634\u2013649 (2009). https:\/\/doi.org\/10.1016\/j.comnet.2008.11.001.","journal-title":"Comput. Netw."},{"issue":"1","key":"1429_CR28","doi-asserted-by":"publisher","first-page":"31","DOI":"10.3390\/fi3010031","volume":"3","author":"H Rif\u00e1-Pous","year":"2011","unstructured":"Rif\u00e1-Pous H., Herrera-Joancomart\u00ed J.: Computational and energy costs of cryptographic algorithms on handheld devices. Future Internet 3(1), 31\u201348 (2011). https:\/\/doi.org\/10.3390\/fi3010031.","journal-title":"Future Internet"},{"key":"1429_CR29","unstructured":"Shoup, V.: On Formal models for secure key exchange. Cryptology ePrint Archive, Report 1999\/012. http:\/\/eprint.iacr.org\/ (1999)."},{"key":"1429_CR30","doi-asserted-by":"publisher","first-page":"102076","DOI":"10.1016\/j.phycom.2023.102076","volume":"59","author":"NR Sivakumar","year":"2023","unstructured":"Sivakumar N.R., Nagarajan S.M., Devarajan G.G., Pullagura L., Mahapatra R.P.: Enhancing network lifespan in wireless sensor networks using deep learning based graph neural network. Phys. Commun. 59, 102076 (2023). https:\/\/doi.org\/10.1016\/j.phycom.2023.102076.","journal-title":"Phys. Commun."},{"key":"1429_CR31","doi-asserted-by":"publisher","first-page":"101254","DOI":"10.1016\/j.phycom.2020.101254","volume":"44","author":"K Song","year":"2021","unstructured":"Song K., Wang Q., Peng L., Li C., Wu X.: Secrecy energy efficiency optimization for df relaying iot systems with passive eavesdropping terminal. Phys. Commun. 44, 101254 (2021). https:\/\/doi.org\/10.1016\/j.phycom.2020.101254.","journal-title":"Phys. Commun."}],"container-title":["Designs, Codes and Cryptography"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10623-024-01429-3.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10623-024-01429-3\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10623-024-01429-3.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,9,18]],"date-time":"2024-09-18T20:19:03Z","timestamp":1726690743000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10623-024-01429-3"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,7,27]]},"references-count":31,"journal-issue":{"issue":"10","published-print":{"date-parts":[[2024,10]]}},"alternative-id":["1429"],"URL":"https:\/\/doi.org\/10.1007\/s10623-024-01429-3","relation":{},"ISSN":["0925-1022","1573-7586"],"issn-type":[{"type":"print","value":"0925-1022"},{"type":"electronic","value":"1573-7586"}],"subject":[],"published":{"date-parts":[[2024,7,27]]},"assertion":[{"value":"15 September 2022","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"7 December 2023","order":2,"name":"revised","label":"Revised","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"17 May 2024","order":3,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"27 July 2024","order":4,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The author does not have competing interests.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interest"}}]}}