Security Analysis and Designing Advanced Two-Party Lattice-Based Authenticated Key Establishment and Key Transport Protocols for Mobile Communication
Abstract
1. Introduction
2. Related Work
- A key transport protocol is a mechanism in which the sender generates a secret session key and securely transfers it to the receiver using a public key encryption scheme or a Key Encapsulation Mechanism (KEM).
- A key agreement protocol enables both the sender and receiver to actively contribute to the generation of a shared session key, typically through an interactive message exchange.
3. Authenticated Key Establishment and Key Transport Protocols
3.1. Authenticated Key Establishment
3.2. Key Transport Protocols
3.3. Importance and Applications
4. Motivation and Contribution
- An authenticated key transport protocol is a cryptographic mechanism that securely delivers a secret key from a sender to a receiver over an insecure channel while ensuring the authenticity of both the key and the communicating parties. The proposed authenticated key transport protocol (see Section 7.4) is an anonymous two-party lattice-based key protocol that enables two parties to communicate without revealing their identities to the adversary.
- These protocols ensure that forward secrecy enables two parties to establish a secret key securely while ensuring that compromise of long-term secret keys does not compromise the confidentiality of past communication. Even if an attacker gains access to a party’s long-term secret key (e.g., a private signing or decryption key), they cannot retroactively decrypt previously recorded communications or derive previously established session keys.
- To ensure real-world security of post-quantum communication protocols, especially on untrusted platforms, resisting signal leakage attacks is as essential as mathematical soundness. This protocol resists well-known signal leakage attacks, and is efficient in both communication and computation overheads.
5. Preliminaries
- for , and
- uniformly random .
6. Statement and Cryptanalysis of Moony et al.’s Protocol [13]
6.1. Key Mismatch Attack on Moony et al.’s Scheme
- computes key:where are random samples.
- fixes and for i, exceptwhere is chosen by .
- computes the value j satisfying (as described in Section 5.4 of [13]).
- Then computes:
- The characteristic function outputs:
- The modular reconciliation function outputs:
- mounts attack as below:
- (a)
- An honest conducts the procedure, purposely switching to 1 such that can assist and infer for some .
- (b)
- The server S receives from along with the necessary parameters.
- After receiving , the server computes:Since changes , then the reconciliation function outputs:
- constructs accessible that observes the server S. The oracle executes the following steps:
- Gets
- Computes
- Computes
- Computes masked value:
- Computes:
- Returns:
- Since is set by , . The result of querying to the oracle with is:from Equation. The sign of is the outcome that imitates ’s sign. Therefore:
- If outputs 1, concludes .
- If outputs 0, concludes .
- The output is 1 when ; then executes another query with :If and , then it returns 1, and outputs .
- To get the sign:
- takes the help of to check negative .
- takes the help of to check positive .
From the above computations for k, if , then:Thus, guesses the correct , and recovers master secret s.
6.2. Unlinkability in Mishra et al.’s Scheme [29]
6.3. Unlinkability and Problem with Error Distribution in Pursharthi et al. [15]
7. Proposed Two-Party Key Establishment and Key Transport Protocols for Mobile Devices
7.1. Setup Phase
- The website server () selects three security parameters: is an integer, a prime q of type, and n-dimensional discrete Gaussian over finite ring with standard deviation .
- The server chooses , and it samples randomly and computes public key ; here s is the master secret of the server.
- The server also chooses a secure collision resistant hashing function that outputs 256 bits, publishes in the public domain, and keeps “s” secret.
7.2. Registration Phase
- The device user chooses arbitrary strings as identity (), password (), and random integer and computes . Further, sends to the server .
- The server receives , computes masked identity , and , and sends the message to the user ().
- The user receives from the server , computes , and recovers masked identity , and a verification factor . Finally, the user () computes the verification value , where p is a suitable prime number, and stores in the device.
7.3. Login and Authenticated Key Establishment Phase (Figure 1)
- The user inputs , , and computes , , and masked identity , checks , and gives permission to be logged into the device.
- The samples random from the n-dimensional Gaussian, and computes , , , , and a verification factor . Finally, the user sends to the server over a public channel.
- The server receives the message , samples , and computes , , , and the masked identity . Furthers, it verifies , and computes , , , and session key . Finally, it computes a verification factor , and sends the message to the corresponding user.
- The receives the message , and computes , , session key . Finally, the user verifies the correctness of the session key by .

7.4. Login and Authenticated Key Transport Phase (Figure 2)
- The user inputs , , and computes , a masked value , masked identity , and it checks , and gives permission to be logged into the device (see Figure 2).
- The user chooses random sample , and computes , , , and . Now, the user computes masked dynamic identity , , and sends to the server.
- The server receives the information from , and computes , , , and . Now, the server verifies whether holds or not. If the information received is correct, then the server computes and chooses the random session key , encrypts it to obtain , and computes , then sends to the user.
- The receives the information from the server, decrypts , and obtains the session key. Finally, the user verifies the session key with , and stores the session key for current communication.

7.5. Proof of Correctness
8. Informal Security Analysis
- Anonymity: An anonymous protocol is a type of communication protocol designed to protect the identity of the participants involved. These protocols are widely used in privacy-preserving applications such as secure messaging, anonymous voting, electronic cash systems, and privacy-preserving authentication in networking systems. In this protocol, the user samples random , computes , , , , and masks the real identity as . Finally, computes verification factor , and sends to the . Since the real identity is masked during communication over a public channel, it is hard for the adversary () to guess the real identity of the user.
- Session key freshness: Session key freshness refers to the guarantee that a newly generated session key is unique and has not been used in any previous communication session. It ensures that each session between parties uses a fresh (i.e., previously unused and unpredictable) key, which is crucial for maintaining confidentiality, forward secrecy, and resistance to replay attacks. In this protocol, the user samples random , computes , , , , and masks the real identity as . Finally, computes verification factor , and sends to the . The server receives the message , computes , , and recovers real identities . Further, it computes , and verifies the information received from the public channel by . Finally, the server chooses a random session key , and transports it to the corresponding user. Since the session key is chosen randomly, and is new for each session, it concludes the freshness.
- Forward Secure: A forward secure protocol (also called forward secrecy or perfect forward secrecy) is a cryptographic protocol designed to ensure that compromise of long-term secret keys does not compromise past session keys. In this protocol, the user samples random , computes , , , , and masks real identity as . Finally, computes verification factor , and sends to the . The server receives the message , computes , , and recovers real identities . Further, it computes , and verifies the information received from the public channel by . Finally, the server chooses a random session key , and transports it to the corresponding user. The session key is dependent on the particular session and is different for other sessions. Therefore, it is not possible to recover previous session keys even if the current session key is compromised.
- Replay Attack: A replay attack occurs when an adversary intercepts and retransmits a previously sent message to trick the receiver into performing an action again or unauthorizedly, without knowing the actual message content or context. An adversary records a valid message exchange between two parties and replays the same message later to impersonate a legitimate user or repeat an operation. In this protocol, the user samples random , computes , , , , and masks the real identity as along with a random number. Finally, computes verification factor , and sends to the . The server receives the message , computes , , and recovers real identities . Further, it computes , and verifies the information received from the public channel by . Finally, the server chooses a random session key , and encrypts it with a random number sent by the user. Therefore, it is not possible to replay older messages.
- Impersonation Attack: An impersonation attack occurs when an adversary pretends to be a legitimate user or entity in a communication protocol to deceive another party, without actually possessing the user’s credentials or secrets. In an impersonation attack, the attacker mimics the identity of a legitimate party (e.g., Alice) and communicates with another party (e.g., Bob) to gain unauthorized access, establish a session, or steal sensitive data. In this protocol, the user samples random , computes , , , , and masks the real identity as . Finally, computes verification factor , and sends to the . The server receives the message , computes , , and recovers real identities . Further, it computes , and inserts it in the verification factor . Thus, it is not possible to impersonate the user or server.
- Man-in-the-Middle (MITM) attack: A protocol is said to be resistant to a Man-in-the-Middle (MITM) attack if it can detect and prevent an adversary from secretly intercepting and altering the communication between two parties without being detected. In an MITM attack, an adversary (Eve) places herself between two parties (Alice and Bob) and modifies, drops, or replaces their messages, often establishing two separate connections:In this protocol, the user samples random , computes , , , , and masks the real identity as . Finally, computes verification factor , and sends to the . The server receives the message , computes , , and recovers real identities . Further, it computes , and inserts it in the verification factor . Finally, the server chooses a random session key , and encrypts it with a random number sent by the user. Therefore, a man-in-the-middle attack is not possible.
- Authenticated key establishment and key transport schemes resist key mismatch attacks: The generatesand transmits to the server . Now, if an adversary has information about the protocol and the ability to submit polynomial times queries to , then it is easy to execute key mismatch attacks to guess the secret key s [13].To get coefficient , the adversary chooses satisfying:Then, runs this protocol and tries to flip the bit of and send it to the server. It is essential to choose satisfying . Further, guesses the sign of , and submits queries. If the sign received is positive, thenIt is interesting to see that this value flips from positive to negative, increasing k whenever , and whenever .In this protocol, the multiplication of is performed with random samples and to get , where controls only, and server controls . Thus, has no control over changing . Therefore,If guesses the sign of is positive, it increases and observes changes from 1 to 0; this flip is not there if:Due to this condition, the proposed protocol resists key mismatch attacks.
9. Formal Security Proof
9.1. Security Model
- Send — Sends a message m to user and receives the response.
- Reveal — Reveals the session key of completed session s.
- Corrupt — Reveals the long-term secret of user .
- Test — The challenge query. A random bit b is chosen. If , the real session key is returned; if , a random string is returned. outputs a guess .
9.2. Assumptions
- Hardness of RLWE: Let be a cyclotomic ring. Given samples for uniformly random , secret , and error e sampled from a discrete Gaussian, no PPT adversary can distinguish these from uniform with non-negligible advantage.
- Hash functions used in the protocol are modeled as random oracles.
9.3. Game-Based Proof
9.3.1. Game
9.3.2. Game
9.3.3. Game
9.3.4. Game
9.4. Advantage Bound
9.4.1. Game 0: Real Protocol Execution
9.4.2. Game 1: Replace Secret with a Random Value
- is given a challenge instance of the hard problem.
- embeds the challenge into the public key or .
- simulates the protocol for and uses ’s output to solve the hard problem.
9.4.3. Game 2: Random Oracle Simulation
9.5. Conclusions
10. Performance Analysis
11. Conclusions/Future Directions
Author Contributions
Funding
Data Availability Statement
Acknowledgments
Conflicts of Interest
References
- Shor, P.W. Algorithms for quantum computation: Discrete logarithms and factoring. In Proceedings of the 35th Annual Symposium on Foundations of Computer Science, Santa Fe, NM, USA, 20–22 November 1994; IEEE: Piscataway, NJ, USA, 1994; pp. 124–134. [Google Scholar]
- Regev, O. Lattice-based cryptography. In Proceedings of the Annual International Cryptology Conference, Santa Barbara, CA, USA, 20–24 August 2006; Springer: Berlin/Heidelberg, Germany, 2006; pp. 131–141. [Google Scholar]
- Lyubashevsky, V.; Peikert, C.; Regev, O. On ideal lattices and learning with errors over rings. In Advances in Cryptology–EUROCRYPT 2010, Proceedings of the 29th Annual International Conference on the Theory and Applications of Cryptographic Techniques, French Riviera, France, 30 May–3 June 2010; Proceedings 29; Springer: Berlin/Heidelberg, Germany, 2010; pp. 1–23. [Google Scholar]
- Mao, W.; Boyd, C. Towards formal analysis of security protocols. In Proceedings of the [1993] Proceedings Computer Security Foundations Workshop VI, Franconia, NH, USA, 15–17 June 1993; IEEE: Piscataway, NJ, USA, 1993; pp. 147–158. [Google Scholar]
- Ding, J.; Xie, X.; Lin, X. A Simple Provably Secure Key Exchange Scheme Based on the Learning with Errors Problem. Cryptology ePrint Archive. 2012. Available online: https://eprint.iacr.org/2012/688.pdf (accessed on 23 September 2025).
- Ding, J.; Alsayigh, S.; Saraswathy, R.; Fluhrer, S.; Lin, X. Leakage of signal function with reused keys in RLWE key exchange. In Proceedings of the 2017 IEEE international conference on communications (ICC), Paris, France, 21–25 May 2017; IEEE: Piscataway, NJ, USA, 2017; pp. 1–6. [Google Scholar]
- Feng, Q.; He, D.; Zeadally, S.; Kumar, N.; Liang, K. Ideal lattice-based anonymous authentication protocol for mobile devices. IEEE Syst. J. 2018, 13, 2775–2785. [Google Scholar] [CrossRef] [Scilit]
- Dharminder, D.; Chandran, K.P. LWESM: Learning with error based secure communication in mobile devices using fuzzy extractor. J. Ambient Intell. Humaniz. Comput. 2020, 11, 4089–4100. [Google Scholar] [CrossRef] [Scilit]
- Dabra, V.; Bala, A.; Kumari, S. LBA-PAKE: Lattice-based anonymous password authenticated key exchange for mobile devices. IEEE Syst. J. 2020, 15, 5067–5077. [Google Scholar] [CrossRef] [Scilit]
- Islam, S.H. Provably secure two-party authenticated key agreement protocol for post-quantum environments. J. Inf. Secur. Appl. 2020, 52, 102468. [Google Scholar] [CrossRef] [Scilit]
- Islam, S.H.; Basu, S. PB-3PAKA: Password-based three-party authenticated key agreement protocol for mobile devices in post-quantum environments. J. Inf. Secur. Appl. 2021, 63, 103026. [Google Scholar] [CrossRef] [Scilit]
- Kumar, U.; Garg, M.; Kumari, S.; Dharminder, D. A construction of post quantum secure and signal leakage resistant authenticated key agreement protocol for mobile communication. Trans. Emerg. Telecommun. Technol. 2023, 34, e4660. [Google Scholar] [CrossRef] [Scilit]
- Moony, B.; Barnwal, A.K.; Singh, M.; Mishra, D. Quantum secure two party authentication protocol for mobile devices. Peer- Netw. Appl. 2023, 16, 2548–2559. [Google Scholar] [CrossRef] [Scilit]
- Seyhan, K.; Akleylek, S. A new lattice-based password authenticated key exchange scheme with anonymity and reusable key. PeerJ Comput. Sci. 2024, 10, e1791. [Google Scholar] [CrossRef] [Scilit]
- Pursharthi, K.; Mishra, D. Towards post-quantum authenticated key agreement scheme for mobile devices. J. Inf. Secur. Appl. 2024, 82, 103754. [Google Scholar] [CrossRef] [Scilit]
- Sarkar, P.; Nag, A. Lattice-based device-to-device authentication and key exchange protocol for IoT system. Int. J. Inf. Technol. 2024, 16, 4167–4179. [Google Scholar] [CrossRef] [Scilit]
- Jiang, C.; Xu, C.; Han, Y.; Zhang, Z.; Chen, K. Two-factor authenticated key exchange from biometrics with low entropy rates. IEEE Trans. Inf. Forensics Secur. 2024, 19, 3844–3856. [Google Scholar] [CrossRef] [Scilit]
- Pursharthi, K.; Mishra, D. A computationally efficient and randomized RLWE-based key exchange scheme. Clust. Comput. 2024, 27, 1599–1610. [Google Scholar] [CrossRef] [Scilit]
- Pursharthi, K.; Mishra, D. Cryptanalysis and amendment of authenticated key exchange protocol for mobile devices. Peer-Netw. Appl. 2025, 18, 108. [Google Scholar] [CrossRef] [Scilit]
- Zhang, J.; Zhang, Z.; Ding, J.; Snook, M.; Dagdelen, Ö. Authenticated key exchange from ideal lattices. In Proceedings of the Advances in Cryptology-EUROCRYPT 2015: 34th Annual International Conference on the Theory and Applications of Cryptographic Techniques, Sofia, Bulgaria, 26–30 April 2015; Proceedings, Part II 34. Springer: Berlin/Heidelberg, Germany, 2015; pp. 719–751. [Google Scholar]
- Fluhrer, S. Cryptanalysis of Ring-LWE Based Key Exchange with Key Share Reuse. Cryptology ePrint Archive. 2016. Available online: https://eprint.iacr.org/2016/085 (accessed on 23 September 2025).
- Chaudhary, D.; Dadsena, P.K.; Pal, Y.; Yadav, D.; Jain, J.; Kumar, M.R.; Preetham, L.M. Security Issues and Solutions in Post Quantum Authenticated Key Exchange for Mobile Devices. In Proceedings of the International Conference on Data Science and Applications, Bandung, Indonesia, 9–10 August 2023; Springer: Berlin/Heidelberg, Germany, 2023; pp. 125–134. [Google Scholar]
- Islam, S.H.; Zeadally, S. Provably secure identity-based two-party authenticated key agreement protocol based on CBi-ISIS and Bi-ISIS problems on lattices. J. Inf. Secur. Appl. 2020, 54, 102540. [Google Scholar] [CrossRef] [Scilit]
- Rana, S.; Mishra, D. Lattice-based key agreement protocol under ring-LWE problem for IoT-enabled smart devices. Sādhanā 2021, 46, 84. [Google Scholar] [CrossRef] [Scilit]
- Akleylek, S.; Soysaldı, M. A new lattice-based authentication scheme for IoT. J. Inf. Secur. Appl. 2022, 64, 103053. [Google Scholar] [CrossRef] [Scilit]
- Wang, Q.; Wang, D.; Cheng, C.; He, D. Quantum2fa: Efficient quantum-resistant two-factor authentication scheme for mobile devices. IEEE Trans. Dependable Secur. Comput. 2021, 20, 193–208. [Google Scholar] [CrossRef] [Scilit]
- Alkim, E.; Ducas, L.; Pöppelmann, T.; Schwabe, P. Post-quantum key {Exchange—A} new hope. In Proceedings of the 25th USENIX security symposium (USENIX Security 16), Austin, TX, USA, 10–12 August 2016; pp. 327–343. [Google Scholar]
- Wang, D.; Wang, P. Two birds with one stone: Two-factor authentication with security beyond conventional bound. IEEE Trans. Dependable Secur. Comput. 2016, 15, 708–722. [Google Scholar] [CrossRef] [Scilit]
- Mishra, D.; Pursharthi, K.; Rewal, P. Development of quantum-enhanced authenticated key agreement protocol for autonomous vehicles. Veh. Commun. 2023, 44, 100688. [Google Scholar] [CrossRef] [Scilit]
- Regev, O. On lattices, learning with errors, random linear codes, and cryptography. J. ACM (JACM) 2009, 56, 34. [Google Scholar] [CrossRef] [Scilit]
- Bellare, M.; Pointcheval, D.; Rogaway, P. Authenticated key exchange secure against dictionary attacks. In Proceedings of the International Conference on the Theory and Applications of Cryptographic Techniques, Bruges, Belgium, 14–18 May 2000; Springer: Berlin/Heidelberg, Germany, 2000; pp. 139–155. [Google Scholar]
- Dharminder, D.; Reddy, C.B.; Das, A.K.; Park, Y.; Jamal, S.S. Post-Quantum Lattice-Based Secure Reconciliation Enabled Key Agreement Protocol for IoT. IEEE Internet Things J. 2022, 10, 2680–2692. [Google Scholar] [CrossRef] [Scilit]


| Aspect | Key Transport Protocols | Key Agreement Protocols |
|---|---|---|
| Interaction | One-way (non-interactive) | Two-way (interactive) |
| Key Generation | Performed by one party | Jointly derived by both |
| Forward Secrecy | Not automatic | Naturally supported |
| Efficiency | Often more compact and faster | Slightly higher overhead |
| Authentication | Needs explicit digital signatures | Can support implicit/explicit |
| Lattice Basis | LWE/Module-LWE + KEM | Ring-LWE + reconciliation |
| Example | Kyber, FrodoKEM | NewHope, BCNS, Lizard |
| Symbols/Notations | Descriptions |
|---|---|
| Finite Degree Ring | |
| Finite Ring | |
| Square Matrix of Order M | |
| Characteristic Function | |
| Modular Function | |
| Euclidean Norm | |
| User | |
| Server | |
| Oracle Queries | |
| Adversary | |
| Random Oracle Model | |
| q | Prime Number |
| n-Dimension Gaussian | |
| Session Key |
| User | Server |
|---|---|
| Public Key: | Public Key: |
| Secret Key: | Secret Key: |
| where | where |
| Components | Details |
|---|---|
| Operating System | Android 13, MIUI 14 |
| Android Version | 13 TKQ1.221114.001 |
| CPU | Snapdragon 680, Octa-core Max 2.40GHz |
| Model | 2201117TI |
| RAM | 6.0+2.0 GB |
| Kernel Version | 4.19.157-perf-gcb1ffc010755 |
| Cores | 8 |
| Components | Details |
|---|---|
| Processor | Intel(R) Core(TM) i5-1035G1 CPU @ 1.00GHz |
| System Type | x64-based pc |
| Graphics | NVIDIA GeForce RTX 2060 |
| RAM | 8gb |
| Clock Speed | 1.00 GHz |
| Crypto Libraries | Miracle, Charm-crypto, NumPy, hash lib |
| Environment | Python 3.9.0 |
| Cores | 8 |
| Operating System | Linux(ubuntu) |
| Schemes | User Side | Server Side |
|---|---|---|
| Computation Cost | Computation Cost | |
| [10] Islam et al. | ||
| [24] Rana et al. | ||
| [32] Dharminder et al. | ||
| [7] Feng et al. | ||
| [9] Dabra et al. | ||
| [26] Wang et al. | ||
| [13] Moony et al. | ||
| [14] Seyhan et al. | ||
| [15] Pursharthi et al. | ||
| [18] Pursharthi et al. | ||
| Proposed scheme |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2025 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (https://creativecommons.org/licenses/by/4.0/).
Share and Cite
Rajendran, M.; Chaudhary, D.; Lakshmanan, S.A.; Lee, C.-C. Security Analysis and Designing Advanced Two-Party Lattice-Based Authenticated Key Establishment and Key Transport Protocols for Mobile Communication. Future Internet 2025, 17, 472. https://doi.org/10.3390/fi17100472
Rajendran M, Chaudhary D, Lakshmanan SA, Lee C-C. Security Analysis and Designing Advanced Two-Party Lattice-Based Authenticated Key Establishment and Key Transport Protocols for Mobile Communication. Future Internet. 2025; 17(10):472. https://doi.org/10.3390/fi17100472
Chicago/Turabian StyleRajendran, Mani, Dharminder Chaudhary, S. A. Lakshmanan, and Cheng-Chi Lee. 2025. "Security Analysis and Designing Advanced Two-Party Lattice-Based Authenticated Key Establishment and Key Transport Protocols for Mobile Communication" Future Internet 17, no. 10: 472. https://doi.org/10.3390/fi17100472
APA StyleRajendran, M., Chaudhary, D., Lakshmanan, S. A., & Lee, C.-C. (2025). Security Analysis and Designing Advanced Two-Party Lattice-Based Authenticated Key Establishment and Key Transport Protocols for Mobile Communication. Future Internet, 17(10), 472. https://doi.org/10.3390/fi17100472

