Anonymous Two-Party Authentication and Key Establishment With Trusted Server for Future-Proofing Security of Mobile Communication System
Dharminder Chaudhary, Uddeshaya Kumar, Saibal Kumar Pal, Gaurav Mittal, Narendra Khatri · IEEE Open Journal of the Communications Society · 2026
In cellular systems, user devices (UEs) establish secure sessions with each other through a trusted server such as the Home Subscriber Server (HSS) or Authentication Center (AuC). The proposed two-party authenticated key establishment allows two users to authenticate and exchange encrypted data with minimal involvement of the server -improving efficiency and scalability in mobile communication. Moreover, this paper presents a cryptanalysis of two post-quantum authentication and key agreement protocols proposed by Dabra et al. and Kumar et al. Our analysis identifies specific weaknesses, a design flaw in the registration phase of Dabra et al.’s protocol, and vulnerabilities to identity guessing and impersonation attacks in Kumar et al.’s scheme. Motivated by these findings, we propose a new communication framework for a two-party authenticated key establishment protocol assisted by a server. In the proposed model, user UA initiates communication by sending a request to a central server and receives a corresponding response to establish an authenticated session key with user UB. Notably, user UB does not need to interact with the server during session initiation or key derivation phases, thereby significantly reducing communication overhead and enhancing efficiency. Through extensive formal analysis and simulation, our protocol achieves 21.37% and 19.99% improvement in computational efficiency and 35.13% and 21.05% reduction in communication overhead compared to the lattice-based authenticated key agreement protocols of Dabra et al. and Kumar et al., respectively. Furthermore, the proposed scheme ensures key freshness, meaning that each session key is unique and has never been used in any prior communication session. This guarantees that every session remains protected by a distinct cryptographic key, even when the same users communicate repeatedly. Additionally, user UA can establish a secure session with user UB without revealing its identity to either UB or any intermediate server, thereby preserving user anonymity. Overall, the proposed protocol offers strong privacy guarantees while enabling secure, authenticated communication with a minimal number of message exchanges.