Decentralized Privacy-Preserving Authenticated Key Exchange Using Real-World Attributes
Abstract
While decentralized authentication mechanisms have gained significant attention for enabling user-centric identity management without centralized authorities, the critical counterpart - authenticated key exchange (AKE) in decentralized settings - remains understudied. Although it forms the basis for secure communication in decentralized scenarios, shifting existing AKE protocols to decentralized settings is impractical: the trust assumption is different, and the insufficient support for dynamic identity attributes, etc. To address these challenges, we present a novel decentralized AKE protocol that innovatively integrates attribute authentication with key exchange through multi-party secure computation. Building upon MPCAuth's foundational framework (S&P 23), our protocol goes further to provide key exchange based on authentication of real-world attributes such as a digital passport and email address, etc. Our protocol establishes a new paradigm for decentralized AKE without complex credential operations and heavy zero-knowledge proof. The core of our protocol is a distributed way to securely reconstruct the attributes and establish a session key. We further evaluate its performance across multiple servers. Experimental results on servers under 5 demonstrate that it can finish the full AKE procedure in an acceptable time, enabling efficient and scalable multi-party key AKE in distributed environments.
Community
0 commentsNo discussion yet
Be the first to share a question or observation.