Passer à la navigation principale Passer à la recherche Passer au contenu principal

Mitigating server breaches in password-based authentication: Secure and efficient solutions

  • XLIM Institut de Recherche
  • Université Paris II
  • PSL research University & IPSL

Résultats de recherche: Le chapitre dans un livre, un rapport, une anthologie ou une collectionContribution à une conférenceRevue par des pairs

8 Citations (Scopus)

Résumé

Password-Authenticated Key Exchange allows users to generate a strong cryptographic key based on a shared “human-memorable” password without requiring a public-key infrastructure. It is one of the most widely used and fundamental cryptographic primitives. Unfortunately, mass password theft from organizations is continually in the news and, even if passwords are salted and hashed, brute force breaking of password hashing is usually very successful in practice. In this paper, we propose two efficient protocols where the password database is somehow shared among two servers (or more), and authentication requires a distributed computation involving the client and the servers. In this scenario, even if a server compromise is doable, the secret exposure is not valuable to the adversary since it reveals only a share of the password database and does not permit to brute force guess a password without further interactions with the parties for each guess. Our protocols rely on smooth projective hash functions and are proven secure under classical assumption in the standard model (i.e. do not require idealized assumption, such as random oracles).

langue originaleAnglais
titreTopics in Cryptology - The Cryptographers Track at the RSA Conference, CT-RSA 2016
rédacteurs en chefKazue Sako
EditeurSpringer Verlag
Pages3-18
Nombre de pages16
ISBN (imprimé)9783319294841
Les DOIs
étatPublié - 1 janv. 2016
Modification externeOui
Evénement2016 Conference on Cryptographer's Track at the RSA, CT-RSA 2016 - San Francisco, États-Unis
Durée: 29 févr. 20164 mars 2016

Série de publications

NomLecture Notes in Computer Science
Volume9610
ISSN (imprimé)0302-9743
ISSN (Electronique)1611-3349

Une conférence

Une conférence2016 Conference on Cryptographer's Track at the RSA, CT-RSA 2016
Pays/TerritoireÉtats-Unis
La villeSan Francisco
période29/02/164/03/16

Empreinte digitale

Examiner les sujets de recherche de « Mitigating server breaches in password-based authentication: Secure and efficient solutions ». Ensemble, ils forment une empreinte digitale unique.

Contient cette citation