A Threshold Multi-Server Protocol for Password-Based Authentication

被引:3
|
作者
Guan, Mengxiang [1 ]
Song, Jiaxing [1 ]
Liu, Weidong [1 ]
机构
[1] Tsinghua Univ, Dept CST, Beijing, Peoples R China
关键词
security; password; authenication;
D O I
10.1109/CSCloud.2016.26
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Password-based user authentication service is widely used in Internet. Most of the password-based authentication protocols are constructed under the single-server structure that a authencitation server stores cleartext passwords or verification data derived from password and responds to users' authentication request. The security of single-server authentication system is very fragile. In particular, when the server is comprimised, all of users' verification data is exposed to the attacker. Nowadays, development of mobile Internet leads the demand of authentication on roaming device. In this scenario, easily memorable short password and simple secret is accepted by most people despite of its security limitation. The utilization of short password worsens the situation of single-server authentication protocol. Attackers controlling the system can launch off-line dictionary attack from internal of server side to obtain users' original password. Multi-server authentication protocols can improve the security of verification data by distributed storing data on the cluster. This approach increases the difficulty of internal attack and guarantees security even if a portion of servers in the cluster are controlled by adversary. But in practice, There are some problems in existing multi-server protocols. For example, communicating with multiple servers brings extra network and computational burden to client device. To address these problems, in this paper we propose a novel password-based multi-server authenication protocol which not only require less computation on client device but remain functional and secure even if adversary controls some servers and forces them collude to attack our protocol.
引用
下载
收藏
页码:108 / 118
页数:11
相关论文
共 50 条
  • [1] SSO password-based multi-server authentication protocol
    Sood, Sandeep K.
    Sarje, Anil K.
    Singh, Kuldip
    INTERNATIONAL JOURNAL OF COMMUNICATION NETWORKS AND DISTRIBUTED SYSTEMS, 2012, 9 (1-2) : 161 - 180
  • [2] Countermeasure on Password-Based Authentication Scheme for Multi-server Environments
    Lee, Youngsook
    Kim, Jiye
    Won, Dongho
    MULTIMEDIA AND UBIQUITOUS ENGINEERING, 2014, 308 : 459 - 466
  • [3] A New Password-Based Multi-server Authentication Scheme Robust to Password Guessing Attacks
    Jia-Lun Tsai
    Nai-Wei Lo
    Tzong-Chen Wu
    Wireless Personal Communications, 2013, 71 : 1977 - 1988
  • [4] A New Password-Based Multi-server Authentication Scheme Robust to Password Guessing Attacks
    Tsai, Jia-Lun
    Lo, Nai-Wei
    Wu, Tzong-Chen
    WIRELESS PERSONAL COMMUNICATIONS, 2013, 71 (03) : 1977 - 1988
  • [5] Quantum-safe multi-server password-based authenticated key exchange protocol
    Chen, Lin
    Qu, Tongzhou
    Yin, Anqi
    MULTIMEDIA TOOLS AND APPLICATIONS, 2024, 83 (24) : 65011 - 65038
  • [6] PASTA: PASsword-based Threshold Authentication
    Agrawal, Shashank
    Miao, Peihan
    Mohassel, Payman
    Mukherjee, Pratyay
    PROCEEDINGS OF THE 2018 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY (CCS'18), 2018, : 2042 - 2059
  • [7] Privacy Preserving Password-Based Multi-server Authenticated Key Agreement Protocol Using Smart Card
    Mishra, Dheerendra
    Dhal, Subhasish
    WIRELESS PERSONAL COMMUNICATIONS, 2018, 99 (01) : 1 - 21
  • [8] An Enhanced Authentication Protocol for Multi-server Environment Using Password and Smart Card
    Sudhakar, T.
    Natarajan, V
    Gopinath, M.
    Saranyadevi, J.
    WIRELESS PERSONAL COMMUNICATIONS, 2020, 115 (04) : 2779 - 2803
  • [9] An Enhanced Authentication Protocol for Multi-server Environment Using Password and Smart Card
    T. Sudhakar
    V. Natarajan
    M. Gopinath
    J. Saranyadevi
    Wireless Personal Communications, 2020, 115 : 2779 - 2803
  • [10] PASSWORD-BASED AUTHENTICATED KEY EXCHANGE PROTOCOL WITHOUT TRUSTED THIRD PARTY FOR MULTI-SERVER ENVIRONMENTS
    Hsu, Chien-Lung
    Wu, Tzong-Sun
    Lin, Han-Yu
    INTERNATIONAL JOURNAL OF INNOVATIVE COMPUTING INFORMATION AND CONTROL, 2012, 8 (3A): : 1541 - 1555