首页> 外文会议>Cryptographers Track at the RSA Conference >Mitigating Server Breaches in Password-Based Authentication: Secure and Efficient Solutions
【24h】

Mitigating Server Breaches in Password-Based Authentication: Secure and Efficient Solutions

机译:缓解服务器在基于密码的身份验证中违反:安全和高效的解决方案

获取原文

摘要

Password-Authenticated Key Exchange allows users to generate a strong cryptographic key based on a shared "human-memorable" password without requiring a public-key infrastructure. It is one of the most widely used and fundamental cryptographic primitives. Unfortunately, mass password theft from organizations is continually in the news and, even if passwords are salted and hashed, brute force breaking of password hashing is usually very successful in practice. In this paper, we propose two efficient protocols where the password database is somehow shared among two servers (or more), and authentication requires a distributed computation involving the client and the servers. In this scenario, even if a server compromise is doable, the secret exposure is not valuable to the adversary since it reveals only a share of the password database and does not permit to brute force guess a password without further interactions with the parties for each guess. Our protocols rely on smooth projective hash functions and are proven secure under classical assumption in the standard model (i.e. do not require idealized assumption, such as random oracles).
机译:密码验证的密钥交换允许用户根据共享的“人类难忘”密码来生成强加密密钥,而无需公开密钥基础架构。它是最广泛使用和最基本的加密基元之一。不幸的是,来自组织的大规模密码盗窃在新闻中,即使是盐渍和哈希密码,密码散列的蛮力打破通常在实践中非常成功。在本文中,我们提出了两个有效的协议,其中密码数据库在两个服务器(或更多)之间的某种方式共享,并且身份验证需要涉及客户端和服务器的分布式计算。在这种情况下,即使服务器妥协是可行的,秘密曝光对于对手而言,由于它只揭示了密码数据库的份额,并且不允许蛮力猜测密码而无需进一步与各方互动的密码。我们的协议依赖于平滑投影散列函数,并在标准模型中经典假设证明是安全的(即,不需要理想化的假设,例如随机oracles)。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号