Huimin Chen, H. Jia, Xia Wu, Xiuli Wang, Maoning Wang
{"title":"Quantum Token for Network Authentication","authors":"Huimin Chen, H. Jia, Xia Wu, Xiuli Wang, Maoning Wang","doi":"10.1109/ICWS53863.2021.00095","DOIUrl":null,"url":null,"abstract":"Classical token-based authentication can play a significant role in the web security check without accessing the database. For example, JSON Web Tokens (JWT) has been used to support scenarios such as single-sign-on. However, with the development of quantum computer, the security of JWT relying on the RSA algorithm would be compromised. Therefore, we propose a protocol to realize network authentication utilizing quantum token. Inspired by the structure of classical JWT, the structure of quantum token also consists of three parts: header, payload and quantum information. After the user logs in successfully, the quantum token can be issued by the server. If the user presents the quantum token to access again during the validity period, the server can verify whether the quantum token is valid. Our quantum token protocol can detect eavesdropping and achieve identity authentication. We also conduct a security analysis of the proposed protocol by addressing possible motives of an Eavesdropper and conclude the approach to be resilient against a broad range of attacks.","PeriodicalId":213320,"journal":{"name":"2021 IEEE International Conference on Web Services (ICWS)","volume":"20 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2021-09-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"3","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2021 IEEE International Conference on Web Services (ICWS)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICWS53863.2021.00095","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 3
Abstract
Classical token-based authentication can play a significant role in the web security check without accessing the database. For example, JSON Web Tokens (JWT) has been used to support scenarios such as single-sign-on. However, with the development of quantum computer, the security of JWT relying on the RSA algorithm would be compromised. Therefore, we propose a protocol to realize network authentication utilizing quantum token. Inspired by the structure of classical JWT, the structure of quantum token also consists of three parts: header, payload and quantum information. After the user logs in successfully, the quantum token can be issued by the server. If the user presents the quantum token to access again during the validity period, the server can verify whether the quantum token is valid. Our quantum token protocol can detect eavesdropping and achieve identity authentication. We also conduct a security analysis of the proposed protocol by addressing possible motives of an Eavesdropper and conclude the approach to be resilient against a broad range of attacks.