{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,10,17]],"date-time":"2024-10-17T04:16:51Z","timestamp":1729138611747,"version":"3.27.0"},"reference-count":47,"publisher":"Institute of Electronics, Information and Communications Engineers (IEICE)","issue":"9","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEICE Trans. Fundamentals"],"published-print":{"date-parts":[[2023,9,1]]},"DOI":"10.1587\/transfun.2022dmp0001","type":"journal-article","created":{"date-parts":[[2023,3,13]],"date-time":"2023-03-13T22:10:46Z","timestamp":1678745446000},"page":"1141-1163","source":"Crossref","is-referenced-by-count":0,"title":["Post-Quantum Anonymous One-Sided Authenticated Key Exchange without Random Oracles"],"prefix":"10.1587","volume":"E106.A","author":[{"given":"Ren","family":"ISHIBASHI","sequence":"first","affiliation":[{"name":"Ibaraki University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Kazuki","family":"YONEYAMA","sequence":"additional","affiliation":[{"name":"Ibaraki University"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"532","reference":[{"key":"1","doi-asserted-by":"crossref","unstructured":"[1] R. Ishibashi and K. Yoneyama, \u201cPost-quantum anonymous one-sided authenticated key exchange without random oracles,\u201d PKC 2022, pp.35-65, 2022. 10.1007\/978-3-030-97131-1_2","DOI":"10.1007\/978-3-030-97131-1_2"},{"key":"2","doi-asserted-by":"publisher","unstructured":"[2] R. Canetti and H. Krawczyk, \u201cAnalysis of key-exchange protocols and their use for building secure channels,\u201d Eurocrypt 2001, pp.453-474, 2001. 10.1007\/3-540-44987-6_28","DOI":"10.1007\/3-540-44987-6_28"},{"key":"3","doi-asserted-by":"crossref","unstructured":"[4] R. Dingledine, N. Mathewson, and P. Syverson, \u201cTor: The second-generation onion router,\u201d 13th USENIX Security Symposium, pp.303-320, 2004.","DOI":"10.21236\/ADA465464"},{"key":"4","doi-asserted-by":"publisher","unstructured":"[5] A. Kwon, D. Lazar, S. Devadas, and B. Ford, \u201cRiffle: An efficient communication system with strong anonymity,\u201d 16th PETS, vol.2016, no.2, pp.115-134, 2016. 10.1515\/popets-2016-0008","DOI":"10.1515\/popets-2016-0008"},{"key":"5","doi-asserted-by":"publisher","unstructured":"[6] I. Goldberg, D. Stebila, and B. Ustaoglu, \u201cAnonymity and one-way authentication in key exchange protocols,\u201d Des. Codes Cryptogr., vol.67, no.2, pp.245-269, 2013. 10.1007\/s10623-011-9604-z","DOI":"10.1007\/s10623-011-9604-z"},{"key":"6","doi-asserted-by":"publisher","unstructured":"[7] D. Diemert and T. Jager, \u201cOn the tight security of TLS 1.3: Theoretically sound cryptographic parameters for real-world deployments,\u201d J. Cryptol., vol.34, p.30, 2021. 10.1007\/s00145-021-09388-x","DOI":"10.1007\/s00145-021-09388-x"},{"key":"7","doi-asserted-by":"crossref","unstructured":"[8] F. Giesen, F. Kohlar, and D. Stebila, \u201cOn the security of TLS renegotiation,\u201d ACM CCS 2013, pp.387-398, 2013. 10.1145\/2508859.2516694","DOI":"10.1145\/2508859.2516694"},{"key":"8","unstructured":"[9] F. Kohlar, S. Sch\u00e4ge, and J. Schwenk, \u201cOn the security of TLS-DH and TLS-RSA in the standard model,\u201d IACR Cryptology ePrint Archive, Report 2013\/367, 2013."},{"key":"9","doi-asserted-by":"crossref","unstructured":"[10] H. Krawczyk and H. Wee, \u201cThe OPTLS protocol and TLS 1.3,\u201d EuroS&amp;P 2016, pp.81-96, 2016. 10.1109\/eurosp.2016.18","DOI":"10.1109\/EuroSP.2016.18"},{"key":"10","doi-asserted-by":"publisher","unstructured":"[11] H. Krawczyk, K.G. Paterson, and H. Wee, \u201cOn the security of the TLS protocol: A systematic analysis,\u201d Crypto 2013, pp.429-448, 2013. 10.1007\/978-3-642-40041-4_24","DOI":"10.1007\/978-3-642-40041-4_24"},{"key":"11","doi-asserted-by":"publisher","unstructured":"[12] \u00d6. Dagdelen, M. Fischlin, T. Gagliardoni, G.A. Marson, A. Mittelbach, and C. Onete, \u201cA cryptographic analysis of OPACITY,\u201d ESORICS 2013, pp.345-362, 2013. 10.1007\/978-3-642-40203-6_20","DOI":"10.1007\/978-3-642-40203-6_20"},{"key":"12","doi-asserted-by":"crossref","unstructured":"[13] P. Morrissey, N. Smart, and B. Warinschi, \u201cA modular security analysis of the TLS handshake protocol,\u201d Asiacrypt 2008, pp.55-73, 2008. 10.1007\/978-3-540-89255-7_5","DOI":"10.1007\/978-3-540-89255-7_5"},{"key":"13","doi-asserted-by":"crossref","unstructured":"[14] Y. Dodis and D. Fiore, \u201cUnilaterally-authenticated key exchange,\u201d Financial Cryptography and Data Security 2017, pp.542-560, 2017. 10.1007\/978-3-319-70972-7_31","DOI":"10.1007\/978-3-319-70972-7_31"},{"key":"14","doi-asserted-by":"crossref","unstructured":"[15] J. Alwen, M. Hirt, U. Maurer, A. Patra, and P. Raykov, \u201cAnonymous authentication with shared secrets,\u201d LATINCRYPT 2014, pp.219-236, 2014. 10.1007\/978-3-319-16295-9_12","DOI":"10.1007\/978-3-319-16295-9_12"},{"key":"15","doi-asserted-by":"crossref","unstructured":"[16] M. Abdalla, M. Izabach\u00e9ne, and D. Pointcheval, \u201cAnonymous and transparent gateway-based password-authenticated key exchange,\u201d CANS 2008, pp.133-148, 2008. 10.1007\/978-3-540-89641-8_10","DOI":"10.1007\/978-3-540-89641-8_10"},{"key":"16","doi-asserted-by":"publisher","unstructured":"[17] M. Lee, N.P. Smart, B. Warinschi, and G.J. Watson, \u201cAnonymity guarantees of the UMTS\/LTE authentication and connection protocol,\u201d Int. J. Inf. Secur., vol.13, pp.513-527, 2014. 10.1007\/s10207-014-0231-3","DOI":"10.1007\/s10207-014-0231-3"},{"key":"17","doi-asserted-by":"crossref","unstructured":"[18] X. Yang, H. Jiang, M. Hou, Z. Zheng, Q. Xu, and K.R. Choo, \u201cA provably-secure two-factor authenticated key exchange protocol with stronger anonymity,\u201d NSS 2018, pp.111-124, 2018. 10.1007\/978-3-030-02744-5_8","DOI":"10.1007\/978-3-030-02744-5_8"},{"key":"18","doi-asserted-by":"publisher","unstructured":"[19] J. Walker and J. Li, \u201cKey exchange with anonymous authentication using DAA-SIGMA protocol,\u201d INTRUST 2010, pp.108-127, 2010. 10.1007\/978-3-642-25283-9_8","DOI":"10.1007\/978-3-642-25283-9_8"},{"key":"19","doi-asserted-by":"crossref","unstructured":"[20] S.S.M. Chow and K.R. Choo, \u201cStrongly-secure identity-based key agreement and anonymous extension,\u201d ISC 2007, pp.203-220, 2007. 10.1007\/978-3-540-75496-1_14","DOI":"10.1007\/978-3-540-75496-1_14"},{"key":"20","doi-asserted-by":"crossref","unstructured":"[21] M. Backes, A. Kate, and E. Mohammadi, \u201cAce: An efficient key-exchange protocol for onion routing,\u201d 11th ACM WPES, pp.55-64, 2012. 10.1145\/2381966.2381974","DOI":"10.1145\/2381966.2381974"},{"key":"21","doi-asserted-by":"crossref","unstructured":"[22] S. Ghosh and A. Kate, \u201cPost-quantum forward-secure onion routing,\u201d ACNS 2015, pp.263-286, 2015. 10.1007\/978-3-319-28166-7_13","DOI":"10.1007\/978-3-319-28166-7_13"},{"key":"22","doi-asserted-by":"publisher","unstructured":"[23] R. Canetti, O. Goldreich, and S. Halevi, \u201cThe random oracle methodology, revisited,\u201d J. ACM, vol.51, no.4, pp.557-594, 2004. 10.1145\/1008731.1008734","DOI":"10.1145\/1008731.1008734"},{"key":"23","doi-asserted-by":"publisher","unstructured":"[24] D. Jao and L.D. Feo, \u201cTowards quantum-resistant cryptosystems from supersingular elliptic curve isogenies,\u201d PQCrypt 2011, pp.19-34, 2011. 10.1007\/978-3-642-25405-5_2","DOI":"10.1007\/978-3-642-25405-5_2"},{"key":"24","doi-asserted-by":"crossref","unstructured":"[25] W. Castryck, T. Lange, C. Martindale, L. Panny, and J. Renes, \u201cCSIDH: An efficient post-quantum commutative group action,\u201d ASIACRYPT 2018, pp.395-427, 2018. 10.1007\/978-3-030-03332-3_15","DOI":"10.1007\/978-3-030-03332-3_15"},{"key":"25","doi-asserted-by":"crossref","unstructured":"[26] A. Fujioka, K. Takashima, S. Terada, and K. Yoneyama, \u201cSupersingular isogeny Diffie-Hellman authenticated key exchange,\u201d ICISC 2018, pp.177-195, 2018. 10.1007\/978-3-030-12146-4_12","DOI":"10.1007\/978-3-030-12146-4_12"},{"key":"26","unstructured":"[27] S.D. Galbraith, \u201cAuthenticated key exchange for SIDH,\u201d IACR Cryptology ePrint Archive, Report 2018\/266, 2018."},{"key":"27","unstructured":"[28] P. Longa, \u201cA note on post-quantum authenticated key exchange from supersingular isogenies,\u201d IACR Cryptology ePrint Archive, Report 2018\/267, 2018."},{"key":"28","doi-asserted-by":"crossref","unstructured":"[29] A. Fujioka, K. Suzuki, K. Xagawa, and K. Yoneyama, \u201cPractical and post-quantum authenticated key exchange from one-way secure key encapsulation mechanism,\u201d AsiaCCS 2013, pp.83-94, 2013. 10.1145\/2484313.2484323","DOI":"10.1145\/2484313.2484323"},{"key":"29","doi-asserted-by":"crossref","unstructured":"[30] C.D.S. Guilhem, N.P. Smart, and B. Warinschi, \u201cGeneric forward-secure key agreement without signatures,\u201d ISC 2017, pp.114-133, 2017. 10.1007\/978-3-319-69659-1_7","DOI":"10.1007\/978-3-319-69659-1_7"},{"key":"30","doi-asserted-by":"crossref","unstructured":"[31] X. Xu, H. Xue, K. Wang, M.H. Au, and S. Tian, \u201cStrongly secure authenticated key exchange from supersingular isogenies,\u201d ASIACRYPT 2019, pp.278-308, 2019. 10.1007\/978-3-030-34578-5_11","DOI":"10.1007\/978-3-030-34578-5_11"},{"key":"31","unstructured":"[32] W. Castryck and T. Decru, \u201cAn efficient key recovery attack on SIDH,\u201d IACR Cryptology ePrint Archive, Report 2022\/975, 2022."},{"key":"32","doi-asserted-by":"crossref","unstructured":"[33] A. Fujioka, K. Takashima, and K. Yoneyama, \u201cOne-round authenticated group key exchange from isogenies,\u201d ProvSec 2019, pp.330-338, 2019. 10.1007\/978-3-030-31919-9_20","DOI":"10.1007\/978-3-030-31919-9_20"},{"key":"33","doi-asserted-by":"crossref","unstructured":"[34] B. de Kock, K. Gj\u00f8steen, and M. Veroni, \u201cPractical isogeny-based key-exchange with optimal tightness,\u201d SAC 2020, pp.451-479, 2020. 10.1007\/978-3-030-81652-0_18","DOI":"10.1007\/978-3-030-81652-0_18"},{"key":"34","doi-asserted-by":"crossref","unstructured":"[35] T. Kawashima, K. Takashima, Y. Aikawa, and T. Takagi, \u201cAn efficient authenticated key exchange from random self-reducibility on CSIDH,\u201d ICISC 2020, pp.58-84, 2020. 10.1007\/978-3-030-68890-5_4","DOI":"10.1007\/978-3-030-68890-5_4"},{"key":"35","doi-asserted-by":"crossref","unstructured":"[36] K. Yoneyama, \u201cOne-round authenticated key exchange with strong forward secrecy in the standard model against constrained adversary,\u201d IWSEC 2012, pp.69-86, 2012. 10.1007\/978-3-642-34117-5_5","DOI":"10.1007\/978-3-642-34117-5_5"},{"key":"36","doi-asserted-by":"publisher","unstructured":"[37] A. Fujioka, K. Suzuki, K. Xagawa, and K. Yoneyama, \u201cStrongly secure authenticated key exchange from factoring, codes, and lattices,\u201d Des. Codes Cryptogr., vol.74, pp.469-504, 2015. 10.1007\/s10623-014-9972-2","DOI":"10.1007\/s10623-014-9972-2"},{"key":"37","doi-asserted-by":"crossref","unstructured":"[38] H. Krawczyk, \u201cHMQV: A high-performance secure Diffie-Hellman protocol,\u201d CRYPTO 2005, pp.546-566, 2005. 10.1007\/11535218_33","DOI":"10.1007\/11535218_33"},{"key":"38","doi-asserted-by":"crossref","unstructured":"[39] D. M&apos;Ra\u00edhi and D. Naccache, \u201cBatch exponentiation: A fast DLP-based signature generation strategy,\u201d ACM CCS 1996, pp.58-61, 1996. 10.1145\/238168.238187","DOI":"10.1145\/238168.238187"},{"key":"39","doi-asserted-by":"publisher","unstructured":"[40] R.M. Avanzi, \u201cThe complexity of certain multi-exponentiation techniques in cryptography,\u201d J. Cryptology, vol.18, pp.357-373, 2005. 10.1007\/s00145-004-0229-5","DOI":"10.1007\/s00145-004-0229-5"},{"key":"40","unstructured":"[41] R. Azarderakhsh, M. Campagna, C. Costello, L.D. Feo, B. Hess, A. Hutchinson, A. Jalali, K. Karabina, B. Koziel, B. LaMacchia, P. Longa, M. Naehrig, G. Pereira, J. Renes, V. Soukharev, and D. Urbanik, \u201cSupersingular isogeny key encapsulation,\u201d NIST Post-Quantum Cryptography Standardization, 2020."},{"key":"41","unstructured":"[42] V. Shoup, \u201cA proposal for an ISO standard for public key encryption,\u201d IACR Cryptology ePrint Archive, Report 2001\/112, 2001."},{"key":"42","doi-asserted-by":"crossref","unstructured":"[43] R. Cramer and V. Shoup, \u201cDesign and analysis of practical public-key encryption schemes secure against adaptive chosen ciphertext attack,\u201d SIAM J. Comput, vol.33, no.1, pp.167-226, 2003. 10.1137\/s0097539702403773","DOI":"10.1137\/S0097539702403773"},{"key":"43","doi-asserted-by":"publisher","unstructured":"[44] K. Yoneyama, \u201cPost-quantum variants of ISO\/IEC standards: Compact chosen ciphertext secure key encapsulation mechanism from isogenies,\u201d IEICE Trans. Fundamentals, vol.E104-A, no.1, pp.69-78, Jan. 2021. 10.1587\/transfun.2020cip0011","DOI":"10.1587\/transfun.2020CIP0011"},{"key":"44","doi-asserted-by":"crossref","unstructured":"[45] T. Moriya, H. Onuki, and T. Takagi, \u201cSigamal: A supersingular isogeny-based PKE and its application to a PRF,\u201d ASIACRYPT 2020, pp.551-580, 2020. 10.1007\/978-3-030-64834-3_19","DOI":"10.1007\/978-3-030-64834-3_19"},{"key":"45","doi-asserted-by":"crossref","unstructured":"[46] N. Alamati, L.D. Feo, H. Montgomery, and S. Patranabis, \u201cCryptographic group actions and applications,\u201d ASIACRYPT 2020, pp.411-439, 2020. 10.1007\/978-3-030-64834-3_14","DOI":"10.1007\/978-3-030-64834-3_14"},{"key":"46","unstructured":"[47] V. Shoup, \u201cSequences of games: A tool for taming complexity in security proofs,\u201d IACR Cryptology ePrint Archive, Report 2004\/332, 2004."},{"key":"47","doi-asserted-by":"crossref","unstructured":"[48] T.B. Fouotsa and C. Petit, \u201cSimS: A simplification of SiGamal,\u201d PQcrypt 2021, pp.277-295, 2021. 10.1007\/978-3-030-81293-5_15","DOI":"10.1007\/978-3-030-81293-5_15"}],"container-title":["IEICE Transactions on Fundamentals of Electronics, Communications and Computer Sciences"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.jstage.jst.go.jp\/article\/transfun\/E106.A\/9\/E106.A_2022DMP0001\/_pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,10,16]],"date-time":"2024-10-16T09:01:05Z","timestamp":1729069265000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.jstage.jst.go.jp\/article\/transfun\/E106.A\/9\/E106.A_2022DMP0001\/_article"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,9,1]]},"references-count":47,"journal-issue":{"issue":"9","published-print":{"date-parts":[[2023]]}},"URL":"https:\/\/doi.org\/10.1587\/transfun.2022dmp0001","relation":{},"ISSN":["0916-8508","1745-1337"],"issn-type":[{"type":"print","value":"0916-8508"},{"type":"electronic","value":"1745-1337"}],"subject":[],"published":{"date-parts":[[2023,9,1]]},"article-number":"2022DMP0001"}}