Pre-Shared Key Authentication with Key Exchange Against Brute-Force Attacks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing identity authentication mechanisms using pre-shared keys are susceptible to dictionary brute force attacks and cannot resist quantum computation attacks, compromising network security.
Innovation Solution
Implement a method involving mutual or unilateral identity authentication between an authentication access controller and a requester using a pre-shared key, combined with a key exchange algorithm to enhance security against such attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a pre-shared key is used for identity authentication, then the authentication mechanism is simple and quick, but it is susceptible to dictionary brute force attacks and cannot meet high security requirements
Solution Approach 1:
The patent combines pre-shared key authentication with public key infrastructure (PKI) technology. The authentication system integrates both symmetric key mechanisms (pre-shared key) and asymmetric key mechanisms (digital certificates), creating a hybrid authentication model that leverages the simplicity of pre-shared keys while adding the security of public key cryptography to resist dictionary brute force attacks
Solution Approach 2:
The authentication mechanism uses a composite approach by combining multiple authentication technologies (pre-shared key + digital certificates + challenge-response protocol). This composite authentication system maintains the operational simplicity of pre-shared keys while incorporating the security strength of multiple cryptographic layers to achieve both ease of operation and high reliability
2Loss of time
If a pre-shared key is used for identity authentication, then the authentication process is quick, but it cannot resist quantum computation attacks
Solution Approach 1:
The patent implements preliminary action by pre-distributing digital certificates and establishing public key pairs before the authentication process. The challenge-response protocol is pre-configured with cryptographic parameters that are computationally hard to break even with quantum computation, allowing quick authentication while providing future-proof quantum resistance
Solution Approach 2:
The authentication system changes the cryptographic parameters from traditional symmetric key algorithms vulnerable to quantum attacks to post-quantum cryptographic algorithms. The challenge-response protocol uses quantum-resistant mathematical problems (such as lattice-based cryptography or hash-based signatures) while maintaining the fast authentication response time through optimized cryptographic operations
Data Source
AI summary
Disclosed in embodiments of the present application are an identity authentication method. Bidirectional or unidirectional identity authentication between an authentication access controller and a requesting device is implemented by using a pre-shared key, thereby laying a foundation for ensuring that a user accessing a network is legitimate and/or a network accessed by a user is legitimate, so as to implement secret communication between the requesting device and the authentication access controller. In addition, in an identity authentication process, a verified party performs calculation on information comprising the pre-shared key of two parties and random numbers respectively generated by the two parties to obtain an identity authentication key, and performs calculation on specified content by using the identity authentication key to obtain an identity authentication code of the verified party. According to the method for calculating an identity authentication code provided by the present application, key exchange calculation is combined, and the capability of resistance to dictionary brute-force attack or to quantum computing attack in the authentication process is enhanced by means of an ingenious detail design. Also disclosed in the embodiments of the present application are an authentication access controller, a requesting device, a storage medium, a program, and a program product.


