首页> 外文会议>Cryptographers' track at the RSA conference >TMPS: Ticket-Mediated Password Strengthening
【24h】

TMPS: Ticket-Mediated Password Strengthening

机译:TMPS:票证中介密码加强

获取原文

摘要

We introduce the notion of TMPS: Ticket-Mediated Password Strengthening, a technique for allowing users to derive keys from passwords while imposing a strict limit on the number of guesses of their password any attacker can make, and strongly protecting the users' privacy. We describe the security requirements of TMPS, and then a set of efficient and practical protocols to implement a TMPS scheme, requiring only hash functions, CCA2-secure encryption, and blind signatures. We provide several variant protocols, including an offline symmetric-only protocol that uses a local trusted computing environment, and online variants that use group signatures or stronger trust assumptions instead of blind signatures. We formalize the security of our scheme by defining an ideal functionality in the Universal Composability (UC) framework, and by providing game-based definitions of security. We prove that our protocol realizes the ideal functionality in the random oracle model (ROM) under adaptive corruptions with erasures, and prove that security with respect to the ideal/real definition implies security with respect to the game-based definitions.
机译:我们引入了TMPS的概念:票务中介的密码强化,该技术允许用户从密码派生密钥,同时严格限制攻击者对密码的猜测次数,并强烈保护用户的隐私。我们描述了TMPS的安全要求,然后描述了一套有效且实用的协议来实现TMPS方案,该协议仅需要哈希函数,CCA2安全加密和盲签名。我们提供了几种变体协议,包括使用本地可信计算环境的仅脱机对称协议,以及使用组签名或更强的信任假设而不是盲目签名的在线变体。通过在通用可组合性(UC)框架中定义理想的功能并提供基于游戏的安全性定义,我们使方案的安全性形式化。我们证明了我们的协议在带有擦除的自适应破坏下,在随机预言模型(ROM)中实现了理想的功能,并证明了相对于理想/真实定义的安全性意味着相对于基于游戏的定义的安全性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号