{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,25]],"date-time":"2026-07-25T16:49:07Z","timestamp":1784998147391,"version":"3.55.0"},"reference-count":23,"publisher":"MDPI AG","issue":"5","license":[{"start":{"date-parts":[[2026,4,24]],"date-time":"2026-04-24T00:00:00Z","timestamp":1776988800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"the Scientific Research Startup Fund for Shenzhen HighCaliber Personnel of SZPT","award":["6022310051K"],"award-info":[{"award-number":["6022310051K"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Entropy"],"abstract":"<jats:p>In emerging environments such as cloud computing and the Internet of Things (IoT), secure authentication and key negotiation play a crucial role in protecting data transmitted over public networks. However, many existing authentication protocols are still designed based on classical public-key cryptography primitives, and quantum computing may threaten their security. To address this challenge, we propose a post-quantum authentication and key agreement protocol that uses the lattice-based Kyber key encapsulation mechanism (KEM). Our proposed protocol integrates cryptographic authentication, smart card protection, and post-quantum key encapsulation mechanisms, enabling mutual authentication between users and servers and securely establishing session keys. The security of the protocol is formally analyzed in the Real-or-Random (ROR) model under the random oracle assumption and the IND-CCA security of the underlying KEM scheme. Furthermore, through informal security analysis, we have further demonstrated that the protocol possesses important security properties, including anonymity, untraceability, perfect forward confidentiality, and resistance to known attacks. In addition, the computational cost and communication overhead of the proposed scheme are evaluated and compared with several representative authentication protocols. The results show that the proposed protocol can provide strong security while maintaining low computational cost and communication overhead.<\/jats:p>","DOI":"10.3390\/e28050490","type":"journal-article","created":{"date-parts":[[2026,5,5]],"date-time":"2026-05-05T11:40:12Z","timestamp":1777981212000},"page":"490","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["A Post-Quantum Authentication and Key Agreement Protocol Based on Lattice-Based KEM for Secure Network Environments"],"prefix":"10.3390","volume":"28","author":[{"given":"Xiaoping","family":"Chen","sequence":"first","affiliation":[{"name":"School of Electronic and Communication Engineering, Shenzhen Polytechnic University, Shenzhen 518055, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0005-8404-9489","authenticated-orcid":false,"given":"Wangyu","family":"Wu","sequence":"additional","affiliation":[{"name":"School of Computer Science, University of Liverpool, Liverpool L69 3DR, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7255-3470","authenticated-orcid":false,"given":"Guangmin","family":"Liang","sequence":"additional","affiliation":[{"name":"School of Electronic and Communication Engineering, Shenzhen Polytechnic University, Shenzhen 518055, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Haonan","family":"Tan","sequence":"additional","affiliation":[{"name":"School of Electronic and Communication Engineering, Shenzhen Polytechnic University, Shenzhen 518055, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0008-6894-6149","authenticated-orcid":false,"given":"Yicheng","family":"Yu","sequence":"additional","affiliation":[{"name":"School of Electronic and Communication Engineering, Shenzhen Polytechnic University, Shenzhen 518055, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2026,4,24]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"100544","DOI":"10.1016\/j.cosrev.2023.100544","article-title":"A survey: When moving target defense meets game theory","volume":"48","author":"Tan","year":"2023","journal-title":"Comput. Sci. Rev."},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"11528","DOI":"10.1109\/TIFS.2025.3601442","article-title":"A strategy-making method for PIoT PLC honeypoint defense against attacks based on the time-delay evolutionary game","volume":"20","author":"Tan","year":"2025","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"320","DOI":"10.1016\/j.future.2016.10.004","article-title":"Design of a provably secure biometrics-based multi-cloud-server authentication scheme","volume":"68","author":"Kumari","year":"2017","journal-title":"Future Gener. Comput. Syst."},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"1003","DOI":"10.1007\/s11277-021-08501-4","article-title":"A biometric based remote user authentication technique using smart card in multi-server environment","volume":"120","author":"Kandar","year":"2021","journal-title":"Wirel. Pers. Commun."},{"key":"ref_5","first-page":"102900","article-title":"PUF enable lightweight key-exchange and mutual authentication protocol for multi-server based D2D communication","volume":"61","author":"Mahmood","year":"2021","journal-title":"J. Inf. Secur. Appl."},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"101389","DOI":"10.1016\/j.iot.2024.101389","article-title":"A quantum-safe authentication scheme for IoT devices using homomorphic encryption and weak physical unclonable functions with no helper data","volume":"28","author":"Arjona","year":"2024","journal-title":"Internet Things"},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Jain, S., Korenda, A.R., Bagri, A., Cambou, B., and Lucero, C.D. (2024). Strengthening industrial IoT security with integrated puf token. Proceedings of the Future Technologies Conference, Springer.","DOI":"10.1007\/978-3-031-73128-0_8"},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"8848032","DOI":"10.1155\/2021\/8848032","article-title":"Provably Secure ECC-Based Three-Factor Authentication Scheme for Mobile Cloud Computing with Offline Registration Centre","volume":"2021","author":"Luo","year":"2021","journal-title":"Wirel. Commun. Mob. Comput."},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Bos, J., Ducas, L., Kiltz, E., Lepoint, T., Lyubashevsky, V., Schanck, J.M., Schwabe, P., Seiler, G., and Stehl\u00e9, D. (2018). CRYSTALS-Kyber: A CCA-secure module-lattice-based KEM. Proceedings of the 2018 IEEE European Symposium on Security and Privacy (EuroS&P), IEEE.","DOI":"10.1109\/EuroSP.2018.00032"},{"key":"ref_10","unstructured":"(2024). Module-Lattice-Based Key-Encapsulation Mechanism Standard (Standard No. FIPS 203)."},{"key":"ref_11","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1007\/s10586-022-03665-5","article-title":"Password authentication key exchange based on key consensus for IoT security","volume":"26","author":"Zhao","year":"2023","journal-title":"Clust. Comput."},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"65011","DOI":"10.1007\/s11042-023-17984-1","article-title":"Quantum-safe multi-server password-based authenticated key exchange protocol","volume":"83","author":"Chen","year":"2024","journal-title":"Multimed. Tools Appl."},{"key":"ref_13","first-page":"101","article-title":"Post-quantum secure authenticated key agreement protocol for wireless sensor networks","volume":"84","author":"Mrityunjay","year":"2023","journal-title":"Telecommun. Syst. Model. Anal. Des. Manag."},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"403","DOI":"10.1007\/s11235-024-01190-x","article-title":"Post-quantum framework for authorized and secure communication in multi-server networking","volume":"87","author":"Pursharthi","year":"2024","journal-title":"Telecommun. Syst."},{"key":"ref_15","doi-asserted-by":"crossref","first-page":"101228","DOI":"10.1016\/j.iot.2024.101228","article-title":"PQCAIE: Post quantum cryptographic authentication scheme for IoT-based e-health systems","volume":"27","author":"Mansoor","year":"2024","journal-title":"Internet Things"},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Franco, C., Arjona, R., and Baturone, I. (2025, January 10\u201313). A Cloud-Based Multifactor Authentication Scheme Using Post-Quantum Cryptography and Trusted Execution Environments. Proceedings of the International Conference on Availability, Reliability and Security, Ghent, Belgium.","DOI":"10.1007\/978-3-032-00642-4_13"},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Bianchi, T., Brighente, A., and Conti, M. (2024, January 27\u201330). DynamiQS: Quantum Secure Authentication for Dynamic Charging of Electric Vehicles. Proceedings of the 17th ACM Conference on Security and Privacy in Wireless and Mobile Networks, Seoul, Republic of Korea.","DOI":"10.1145\/3643833.3656115"},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"107634","DOI":"10.1016\/j.future.2024.107634","article-title":"Flexible hybrid post-quantum bidirectional multi-factor authentication and key agreement framework using ECC and KEM","volume":"166","author":"Braeken","year":"2025","journal-title":"Future Gener. Comput. Syst."},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Sikeridis, D., Kampanakis, P., and Devetsikiotis, M. (2020, January 1\u20134). Assessing the Overhead of Post-Quantum Cryptography in TLS 1.3 and SSH. Proceedings of the 16th International Conference on emerging Networking EXperiments and Technologies, Barcelona, Spain.","DOI":"10.1145\/3386367.3431305"},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Schwabe, P., Stebila, D., and Wiggers, T. (2020, January 9\u201313). Post-Quantum TLS Without Handshake Signatures. Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security, Virtual.","DOI":"10.1145\/3372297.3423350"},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"150","DOI":"10.1016\/j.dcan.2021.07.002","article-title":"An enhanced scheme for mutual authentication for healthcare services","volume":"8","author":"Shamshad","year":"2022","journal-title":"Digit. Commun. Netw."},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Wen, Y., Su, Y., and Li, W. (2025). Post-quantum secure multi-factor authentication protocol for multi-server architecture. Entropy, 27.","DOI":"10.3390\/e27070765"},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"065207","DOI":"10.1088\/1612-202X\/ad3f96","article-title":"Measurement-free mediated semi-quantum key distribution protocol based on single-particle states","volume":"21","author":"Zhou","year":"2024","journal-title":"Laser Phys. Lett."}],"container-title":["Entropy"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1099-4300\/28\/5\/490\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,13]],"date-time":"2026-05-13T04:15:26Z","timestamp":1778645726000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1099-4300\/28\/5\/490"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,4,24]]},"references-count":23,"journal-issue":{"issue":"5","published-online":{"date-parts":[[2026,5]]}},"alternative-id":["e28050490"],"URL":"https:\/\/doi.org\/10.3390\/e28050490","relation":{},"ISSN":["1099-4300"],"issn-type":[{"value":"1099-4300","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,4,24]]}}}