Threshold password-authenticated key exchange

被引:32
作者
MacKenzie, P [1 ]
Shrimpton, T
Jakobsson, M
机构
[1] Bell Labs, Lucent Technol, Murray Hill, NJ 07974 USA
[2] Portland State Univ, Dept Comp Sci, Portland, OR 97207 USA
[3] Indiana Univ, Sch Informat, Bloomington, IN 47408 USA
关键词
password authentication; key exchange; threshold cryptosystems; dictionary attack;
D O I
10.1007/s00145-005-0232-5
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
In most password-authenticated key exchange systems there is a single server storing password verification data. To provide some resilience against server compromise, this data typically takes the form of a one-way function of the password (and possibly a salt, or other public values) rather than the password itself. However, if the server is compromised, this password verification data can be used to perform an off-line dictionary attack on the user's password. In this paper we propose an efficient password-authenticated key exchange system involving a set of servers with known public keys, in which a certain threshold of servers must participate in the authentication of a user, and in which the compromise of any fewer than that threshold of servers does not allow an attacker to perform an off-line dictionary attack. We prove our system is secure in the random oracle model under the Decision Diffie-Hellman assumption against an attacker that may eavesdrop on, insert, delete, or modify messages between the user and servers, and that compromises fewer than that threshold of servers.
引用
收藏
页码:27 / 66
页数:40
相关论文
共 38 条
  • [31] Strong password-only authenticated key exchange
    Jablon, D.P.
    [J]. Computer Communication Review, 1996, 26 (05): : 5 - 26
  • [32] Jablon DP, 2001, LECT NOTES COMPUT SC, V2020, P344
  • [33] Katz J, 2001, LECT NOTES COMPUT SC, V2045, P475
  • [34] MacKenzie P, 2000, LECT NOTES COMPUT SC, V1976, P599
  • [35] NAOR M, 1990, PROCEEDINGS OF THE TWENTY SECOND ANNUAL ACM SYMPOSIUM ON THEORY OF COMPUTING, P427, DOI 10.1145/100216.100273
  • [36] Sahai A., 1999, 40th Annual Symposium on Foundations of Computer Science (Cat. No.99CB37039), P543, DOI 10.1109/SFFCS.1999.814628
  • [37] *SSH, 2001, SSH COMM SEC
  • [38] Wu Thomas D, 1998, NDSS, V98, P97