首页> 外文会议>International Conference on Security, Privacy, and Applied Cryptography Engineering >PAS-TA-U: PASsword-Based Threshold Authentication with Password Update
【24h】

PAS-TA-U: PASsword-Based Threshold Authentication with Password Update

机译:PAS-TA-U:基于密码的阈值身份验证,密码更新

获取原文

摘要

A single-sign-on (SSO) is an authentication system that allows a user to log in with a single identity and password to any of several related, yet independent, server applications. SSO solutions eliminate the need for users to repeatedly prove their identities to different applications and hold different credentials for each application. Token-based authentication is commonly used to enable a SSO experience on the web, and on enterprise networks. A large body of work considers distributed token generation which can protect the long term keys against a subset of breached servers. A recent work (CCS'18) introduced the notion of Password-based Threshold Authentication (PbTA) with the goal of making password-based token generation for SSO secure against server breaches that could compromise both long-term keys and user credentials. They also introduced a generic framework called PASTA that can instantiate a PbTA system. The existing SSO systems built on distributed token generation techniques, including the PASTA framework, do not admit password-update functionality. In this work, we address this issue by proposing a password-update functionality into the PASTA framework. We call the modified framework PAS-TA-U. As a concrete application, we instantiate PAS-TA-U to implement in Python a distributed SSH key manager for enterprise networks (ESKM) that also admits a password-update functionality for its clients. Our experiments show that the overhead of protecting secrets and credentials against breaches in our system compared to a traditional single server setup is low (average 119 ms in a 10-out-of-10 server setting on Internet with 80 ms round trip latency).
机译:单点登录(SSO)是一个身份验证系统,允许用户使用单个标识和密码登录到多个相关但独立的服务器应用程序中的任何一个。 SSO解决方案消除了用户对不同应用程序反复证明其身份的需求,并为每个应用程序保持不同的凭据。基于令牌的身份验证通常用于在Web上和企业网络上启用SSO体验。大型工作主体考虑了分布式令牌生成,可以保护长期键免受破坏服务器的子集。最近的工作(CCS'18)引入了基于密码的阈值身份验证(PBTA)的概念,其目标是为SSO对服务器漏洞进行安全的基于密码的令牌生成,这可能会损害长期键和用户凭据。他们还推出了一个称为意大利面的通用框架,可以实例化PBTA系统。内置于分布式令牌生成技术的现有SSO系统,包括面食框架,不承认密码更新功能。在这项工作中,我们通过将密码更新功能提出进入意大利面框框架来解决此问题。我们称修改过的框架PAS-TA-U。作为一个具体的应用,我们将PAS-TA-U实例化在Python中实现用于企业网络(ESKM)的分布式SSH密钥管理器,也承认其客户端的密码更新功能。我们的实验表明,与传统的单服务器设置相比,我们系统中防止漏洞保护秘密和凭证的开销是低的(在Internet上的100多个服务器设置中平均119毫秒,具有80毫秒往返延迟)。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号