PQ3FAKE: Postquantum Three-Factor Authentication Against Server Compromise in Mobile Cloud Computing
Xue Yang, Qi Gang Jiang, Meng Li, Meijia Xu, Ding Wang, Jianfeng Ma · IEEE Internet of Things Journal · 2025
The rapid advancement of mobile cloud computing has prompted users and commercial entities to increasingly access and utilize cloud resources for executing resource-intensive operations, which requires strong three-factor authentication and key exchange (3FAKE) protocols to ensure secure interactions in cloud environments. However, the current 3FAKE protocols not only primarily rely on traditional public-key cryptosystems that are vulnerable to quantum attacks, but lack sufficient protection for sensitive information of cloud users as well. To this end, this paper proposes a post-quantum 3FAKE (PQ3FAKE) protocol employing identity-based oblivious pseudorandom function (IBOPRF). Specifically, an IBOPRF from module learning with errors is instantiated to achieve a better balance between efficiency and security. Next, PQ3FAKE is built upon this IBOPRF to protect password from server compromise. We conduct an extensive evaluation and comparison with existing typical protocols in terms of computational overhead and security, demonstrating that the proposed PQ3FAKE achieves higher security while maintaining expected performance.