【24h】

AuthStore: Password-Based Authentication and Encrypted Data Storage in Untrusted Environments

机译:AuthStore:在不受信任的环境中基于密码的身份验证和加密的数据存储

获取原文
获取原文并翻译 | 示例

摘要

Passwords are widely used for client to server authentication as well as for encrypting data stored in untrusted environments, such as cloud storage. Both, authentication and encrypted cloud storage, are usually discussed in isolation. In this work, we propose AuthStore, a flexible authentication framework that allows users to securely reuse passwords for authentication as well as for encrypted cloud storage at a single or multiple service providers. Users can configure how secure passwords are protected using password stretching techniques. We present a compact password-authenticated key exchange protocol (CompactPAKE) that integrates the retrieval of password stretching parameters. A parameter attack is described and we show how existing solutions suffer from this attack. Furthermore, we introduce a password manager that supports CompactPAKE.
机译:密码广泛用于客户端到服务器的身份验证以及加密存储在不可信环境(例如云​​存储)中的数据。身份验证和加密的云存储通常都单独讨论。在这项工作中,我们提出了AuthStore,这是一个灵活的身份验证框架,允许用户安全地重用密码进行身份验证以及在单个或多个服务提供商处进行加密的云存储。用户可以配置使用密码扩展技术保护安全密码的方式。我们提出了一个紧凑的经过密码验证的密钥交换协议(CompactPAKE),该协议集成了密码扩展参数的检索。描述了参数攻击,我们展示了现有解决方案如何遭受这种攻击。此外,我们介绍了支持CompactPAKE的密码管理器。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号