Anonymous Authenticated Key Exchange
José Ignacio Escribano Pablos, María Isabel González Vasco, Ángel Luis Pérez del Pozo, Claudio Soriente · Lecture notes in computer science · 2025
Abstract Authenticated Key Exchange ( $${\textsf {AKE}}$$ AKE ) can be used in client-server applications for mutual authentication and key establishment. In scenarios where client authentication is neither feasible nor desirable, One-Sided AKE ( $${\textsf {OS-AKE}}$$ OS - AKE ) allows both parties to establish a key while only the server authenticates to the client. Thus, $${\textsf {OS-AKE}}$$ OS - AKE provides client anonymity with respect to the server, but does not allow the server to enforce any form of access control—that is, the server simply establishes a key with any client. In this paper, we introduce Anonymous AKE ( $${\textsf {A-AKE}}$$ A - AKE ) to strike a balance between classical client authentication of $${\textsf {AKE}}$$ AKE and client anonymity of $${\textsf {OS-AKE}}$$ OS - AKE . In a nutshell $${\textsf {A-AKE}}$$ A - AKE is an $${\textsf {AKE}}$$ AKE protocol where (i) the server authenticates to the client, (ii) the server can enforce access control by deciding which clients are authorized to run the key-establishment protocol, (iii) a key is established between the server and the client only if the latter is one of the authorized clients as defined by the server, and (iv) the authorized client remains anonymous (within the set of all authorized clients) with respect to the server. We introduce a security model for $${\textsf {A-AKE}}$$ A - AKE that extends popular $${\textsf {AKE}}$$ AKE models and design a general framework for instantiating $${\textsf {A-AKE}}$$ A - AKE protocols based on well-established cryptographic primitives. Finally, we instantiate several $${\textsf {AKE}}$$ AKE protocols aiming at strong security guarantees in the classical and post-quantum settings. We implement a prototype of each instantiation and provide an experimental comparison of their performance.