Post-quantum password authenticated key exchange schemes and their primitives for resource-constrained devices
Tez Türü: Doktora
Tezin Yürütüldüğü Kurum: Ondokuz Mayıs Üniversitesi, Lisansüstü Eğitim Enstitüsü, Türkiye
Tez Danışmanı: Prof. Dr. Sedat Akleylek
Tezin Onay Tarihi: 2024
Tezin Dili: İngilizce
Desteklendiği Program: Diğer
Özet:
In this thesis, the aim is to propose password-based authenticated key exchange (PAKE) solutions with lattice primitives for post-quantum era security. Within the scope of the thesis, lattice-based PAKEs are systematically examined and new hard lattice problem-based schemes, Saber.PAKE, Kyber.PAKE, and BiGISIS.PAKE, are proposed by following different design ideas, components, and properties from the current literature. Saber.PAKE, the first lattice-based PAKE scheme based on the module learning with rounding problem, is constructed by combining the well-defined key exchange model based on simple operations and the one-phase PAKE design idea. A detailed security analysis against dictionary attacks is presented by updating module learning with rounding-based random oracle assumptions. Kyber.PAKE is designed as a one-phase PAKE by utilizing key encapsulation components of Kyber, the post-quantum era key encapsulation mechanism standard of the National Institute of Standards and Technology. A detailed security analysis is carried out on the modul learning with errors-based random oracle model assumptions and real world compatible password behaviors. BiGISIS.PAKE is the first four-phase lattice-based PAKE scheme without signal leakage attack vulnerability that provides anonymity and reusable key with the help of reconciliation structure and bilateral-pasteurization method. The security of BiGISIS.PAKE is analyzed in detail under the real-or-random-based model. The implementations of Saber.PAKE and Kyber.PAKE are given for different platforms. As a result of experimental results, Saber.PAKE comes to the fore with better run-time results, while Kyber.PAKE provides relatively efficient run times for high-level post-quantum security of different proposes, even if it has complex key encapsulation mechanism structures. To understand the applicability/usability of post-quantum schemes for resource-constrained devices, comprehensive analyses are done using current methods for resource constraints and random number requirements. By proposing a sensitive resource classification, the usability of lattice-based cryptosystems for commonly used Internet of things devices is examined. In addition, up-to-date literature and real-world random number generator solutions constructed for resource-constrained devices are discussed regarding the methods for ensuring randomness, the strength of randomness, and basic characteristics.