Paper 2025/905

Authenticated Key Exchange Protocol with Remote Randomness

John C. W. Chan, City University of Hong Kong
Abstract

A conventional Authenticated Key Exchange (AKE) protocol consumes fresh random coins from the local random source. However, recent studies of bad randomness expose the vulnerability of some AKE protocols under small subgroup attacks when the random coins are manipulated or being repeated. It is important to ensure the bad randomness of one random source will not affect the security of the AKE protocol as a whole. Thus, we introduce the notion of remote randomness by introducing additional ephemeral keys generated by a fresh remote random source in the AKE protocol. In this paper, we argue that because of the thrive of cloud computing, it encourages high speed internal data transfer within server clusters or virtual machines, including entropy pool data used in our remote randomness AKE protocols. We present a remote randomness modification to the HMQV protocol to demonstrate its resilience under the manipulation of local random sources. We then provide a new security model with the consideration of remote randomness and show thatthe modified AKE protocol is secure under our new model.

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
Preprint.
Keywords
CryptographyRemote RandomnessRemote Randomness ModelRemote Randomness ProtocolRHMQV
Contact author(s)
johnchan713 @ gmail com
History
2025-05-21: approved
2025-05-21: received
See all versions
Short URL
https://ia.cr/2025/905
License
Creative Commons Attribution-NonCommercial-ShareAlike
CC BY-NC-SA

BibTeX

@misc{cryptoeprint:2025/905,
      author = {John C. W. Chan},
      title = {Authenticated Key Exchange Protocol with Remote Randomness},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/905},
      year = {2025},
      url = {https://eprint.iacr.org/2025/905}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.