【24h】

tPAKE: Typo-Tolerant Password-Authenticated Key Exchange

机译:TPAKE:典型的密码验证密钥交换

获取原文
获取外文期刊封面目录资料

摘要

Password-authenticated key exchange (PAKE) enables a user to authenticate to a server by proving the knowledge of the password without actually revealing their password to the server. PAKE protects user passwords from being revealed to an adversary who compromises the server (or a disgruntled employee). Existing PAKE protocols, however, do not allow even a small typographical mistake in the submitted password, such as accidentally adding a character at the beginning or at the end of the password. Logins are rejected for such password submissions; the user has to retype their password and reengage in the PAKE protocol with the server. Prior works have shown that users often make typographical mistakes while typing their passwords. Allowing users to log in with small typographical mistakes would improve the usability of passwords and help users log in faster. Towards this, we introduce tPAKE: a typo-tolerant PAKE, that allows users to authenticate (or exchange high-entropy keys) using a password while tolerating small typographical mistakes. tPAKEallows edit-distance-based errors, but only those that are frequently made by users. This benefits security, while still improving usability. We discuss the security considerations and challenges in designing tPAKE. We implement tPAKE and show that it is computationally feasible to be used in place of traditional PAKEs while providing improved usability. We also provide an extension to tPAKE, called adaptive-tPAKE, that will enable the server to allow a user to log in with their frequent mistakes (without ever learning those mistakes).
机译:密码验证密钥交换(PANK)使用户能够通过证明密码的知识来对服务器进行身份验证,而无需实际将其密码显示到服务器。偷猎保护用户密码被揭示给妥协服务器(或不满员工)的对手。但是,现有的豁免协议不允许在提交的密码中甚至是一个小的印刷错误,例如意外地在密码开始或结束时添加字符。登录被拒绝用于此类密码提交;用户必须在与服务器中重新键入他们的密码并重新登记。先前的作品表明,用户在键入密码时经常在打印错误。允许用户使用小的印刷错误登录将提高密码的可用性,并帮助用户更快地登录。为此,我们介绍了TPAKE:一种宽容的普及,允许用户使用密码进行身份验证(或交换高熵键),同时容忍小的印刷错误。 Tpakeallows基于距离的错误,但只有用户经常制作的错误。这有利于安全性,同时仍在提高可用性。我们讨论了设计TPAKE的安全考虑因素和挑战。我们实施TPAKE并表明它可以在计算上用于代替传统令人争论,同时提供改善的可用性。我们还向TPake提供扩展,称为Adaptive-TPAKE,这将使服务器能够允许用户使用频繁错误(不学习这些错误)。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号