Authenticated Key Transport Protocol Based on a Locking-Signing Technique
Jun Yang, Xianze Yang, Nan Zhang · 2009
Key distribution is one of the fundamental issues in modern cryptography and its security is the main concern in World Wide Web-based applications. In this paper, a new type of secure key transport protocol with a no-key encryption, locking and signing technique is proposed based on Shamir's and Khayat's protocols. The basic security rests on the difficulty of the discrete logarithm problem and random numbers for challenge-response are utilized to detect replay and impersonation, providing mutual entity authentication and explicit key authentication. Compared with the Beller-Yacobi's protocol, two parties sharing no a priori keying material can end up with a shared secret key without performing asymmetric encryption and it is immune to the man-in-the-middle attack. Analysis also shows that expensive cost of computing all the inverses of underlying group elements can be avoided by performing pre-computation, facilitating on-line key establishment.