Multi-Factor Key Derivation Function (MFKDF) for Fast, Flexible, Secure, & Practical Key Management

被引:0
|
作者
Nair, Vivek [1 ]
Song, Dawn [1 ]
机构
[1] Univ Calif Berkeley, Berkeley, CA 94720 USA
来源
PROCEEDINGS OF THE 32ND USENIX SECURITY SYMPOSIUM | 2023年
基金
美国国家科学基金会;
关键词
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
We present the first general construction of a Multi-Factor Key Derivation Function (MFKDF). Our function expands upon password-based key derivation functions (PBKDFs) with support for using other popular authentication factors like TOTP, HOTP, and hardware tokens in the key derivation process. In doing so, it provides an exponential security improvement over PBKDFs with less than 12 ms of additional computational overhead in a typical web browser. We further present a threshold MFKDF construction, allowing for client-side key recovery and reconstitution if a factor is lost. Finally, by "stacking" derived keys, we provide a means of cryptographically enforcing arbitrarily specific key derivation policies. The result is a paradigm shift toward direct cryptographic protection of user data using all available authentication factors, with no noticeable change to the user experience. We demonstrate the ability of our solution to not only significantly improve the security of existing systems implementing PBKDFs, but also to enable new applications where PBKDFs would not be considered a feasible approach.
引用
收藏
页码:2097 / 2114
页数:18
相关论文
共 50 条
  • [41] Multi-Factor One-Way Authentication and Key Retrieval Based on Ideal Threshold Secret Sharing
    Shenets, N.
    NONLINEAR PHENOMENA IN COMPLEX SYSTEMS, 2020, 23 (01): : 54 - 65
  • [42] Comments on “A Multi-factor User Authentication and Key Agreement Protocol Based on Bilinear Pairing for the Internet of Things”
    Salman Shamshad
    Khalid Mahmood
    Saru Kumari
    Wireless Personal Communications, 2020, 112 : 463 - 466
  • [43] A Secure and Efficient Multi-Factor Mutual Certificateless Authentication with Key Agreement Protocol for Mobile Client-Server Environment on ECC without the third-party
    Cao, Liling
    Ge, Wancheng
    INTERNATIONAL JOURNAL OF SECURITY AND ITS APPLICATIONS, 2016, 10 (10): : 215 - 226
  • [44] A Secure Three-Factor Authenticated Key Agreement Scheme for Multi-Server Environment
    Xia, Meichen
    Li, Shiliang
    Liu, Liu
    CMC-COMPUTERS MATERIALS & CONTINUA, 2020, 64 (03): : 1673 - 1689
  • [45] MAKA: Multi-Factor Authentication and Key Agreement Scheme for LoRa-Based Smart Grid Communication Services
    Mehta, Prarthana J.
    Parne, Balu L.
    Patel, Sankita J.
    IETE JOURNAL OF RESEARCH, 2024, 70 (05) : 4989 - 5005
  • [46] Multi-factor user authentication and key agreement scheme for wireless sensor networks using Chinese remainder theorem
    Tyagi, Gaurav
    Kumar, Rahul
    PEER-TO-PEER NETWORKING AND APPLICATIONS, 2023, 16 (01) : 260 - 276
  • [47] Multi-factor user authentication and key agreement scheme for wireless sensor networks using Chinese remainder theorem
    Gaurav Tyagi
    Rahul Kumar
    Peer-to-Peer Networking and Applications, 2023, 16 : 260 - 276
  • [48] Secure Multi-Key Generation Using Ring Oscillator based Physical Unclonable Function
    Yanambaka, Venkata P.
    Mohanty, Saraju P.
    Kougianos, Elias
    Singh, Jawar
    PROCEEDINGS OF 2016 IEEE INTERNATIONAL SYMPOSIUM ON NANOELECTRONIC AND INFORMATION SYSTEMS (INIS), 2016, : 200 - 205
  • [49] Secure Energy Aware Multi-path Routing With Key Management in Wireless Sensor Network
    Saikia, Monjul
    Das, Uddipta Kaishyap
    Hussain, Md Anwar
    2017 4TH INTERNATIONAL CONFERENCE ON SIGNAL PROCESSING AND INTEGRATED NETWORKS (SPIN), 2017, : 310 - 315
  • [50] Secure Data Deduplication System with Efficient and Reliable Multi-Key Management in Cloud Storage
    Vignesh, R.
    Preethi, J.
    JOURNAL OF INTERNET TECHNOLOGY, 2022, 23 (04): : 811 - 825