A Cloud-Based Multifactor Authentication Scheme Using Post-Quantum Cryptography and Trusted Execution Environments


연구 분야: Cryptography



학회: International Conference on Availability, Reliability and Security


초록

Since online transactions increase every day (banking, health services, etc.), authenticating the users in the cloud with a high level of assurance is a big concern. We propose a multifactor authentication scheme using post-quantum cryptography and trusted execution environments (TEEs). Three authentication factors are considered: what the user has (a device storing a secret), what the user knows (a password) and who the user is (with face biometrics). CRYSTALS-Kyber post-quantum public-key encryption is executed in an enclave of a TEE to encrypt a combination of the three factors mentioned. Instead of using the closed TEE solutions available in some personal devices, we propose an open solution that implements each personal enclave (linked to each personal device) in a biometric server. Instead of using a local authentication to unlock a personal device, we propose the use of another server (an authentication server), with another enclave, to authenticate each user in the cloud. The sensitive information concerning biometrics is always protected in a post-quantum manner, not only because it is obtained and encrypted inside an enclave on a biometric server but also because it is communicated, stored, and processed at the authentication server without being decrypted, thanks to the homomorphic property of Kyber. Our proposal is scalable for many users and secure against malicious adversaries. Experimental results using Intel SGX1 enclaves disabling hyper-threading and a facial recognition system show that the time to perform the crypto-biometric operations (excluding the feature extraction) is 1.55 ms and the accuracy considering only the biometric factor is 99.2% with an EER of 1.18%, which are competitive results compared to the state-of-the-art.


Author Profile
Claudia Franco

Instituto de Microelectrónica de Sevilla (IMSE-CNM) University of Seville-CSIC Seville Spain

Germany
Author Profile
Rosario Arjona

Instituto de Microelectrónica de Sevilla (IMSE-CNM) University of Seville-CSIC Seville Spain

Germany
Author Profile
Iluminada Baturone

Instituto de Microelectrónica de Sevilla (IMSE-CNM) University of Seville-CSIC Seville Spain

Germany

📄 논문 정보

발행 연도 2025년
인용수 0
출판 국가 Germany
사이트 Springer
좋아요 수 0

연관 논문 목록 (403건)