A Threshold Multi-Server Protocol for Password-Based Authentication

被引:3
|
作者
Guan, Mengxiang [1 ]
Song, Jiaxing [1 ]
Liu, Weidong [1 ]
机构
[1] Tsinghua Univ, Dept CST, Beijing, Peoples R China
关键词
security; password; authenication;
D O I
10.1109/CSCloud.2016.26
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Password-based user authentication service is widely used in Internet. Most of the password-based authentication protocols are constructed under the single-server structure that a authencitation server stores cleartext passwords or verification data derived from password and responds to users' authentication request. The security of single-server authentication system is very fragile. In particular, when the server is comprimised, all of users' verification data is exposed to the attacker. Nowadays, development of mobile Internet leads the demand of authentication on roaming device. In this scenario, easily memorable short password and simple secret is accepted by most people despite of its security limitation. The utilization of short password worsens the situation of single-server authentication protocol. Attackers controlling the system can launch off-line dictionary attack from internal of server side to obtain users' original password. Multi-server authentication protocols can improve the security of verification data by distributed storing data on the cluster. This approach increases the difficulty of internal attack and guarantees security even if a portion of servers in the cluster are controlled by adversary. But in practice, There are some problems in existing multi-server protocols. For example, communicating with multiple servers brings extra network and computational burden to client device. To address these problems, in this paper we propose a novel password-based multi-server authenication protocol which not only require less computation on client device but remain functional and secure even if adversary controls some servers and forces them collude to attack our protocol.
引用
收藏
页码:108 / 118
页数:11
相关论文
共 50 条
  • [21] Efficient password authentication schemes based on a geometric approach for a multi-server environment
    Liaw, Horng-Twu
    Yen, Chih-Ta
    Chiu, Meng-Yu
    Hsiao, Li-Lin
    JOURNAL OF ZHEJIANG UNIVERSITY-SCIENCE C-COMPUTERS & ELECTRONICS, 2010, 11 (12): : 989 - 997
  • [22] A password and smart card based user authentication mechanism for multi-server environments
    Department of Information Management, Tainan University of Technology, 529 Zhongzheng Road, Tainan City 71002, Taiwan
    不详
    不详
    不详
    Int. J. Future Gener. Commun. Networking, 4 (153-164):
  • [23] Efficient password authentication schemes based on a geometric approach for a multi-server environment
    Horng-Twu LIAW
    Chih-Ta YEN
    Meng-Yu CHIU
    Li-Lin HSIAO
    Frontiers of Information Technology & Electronic Engineering, 2010, (12) : 989 - 997
  • [24] Cryptanalysis of two ID based password authentication schemes for multi-server environments
    Tan Z.
    International Journal of Digital Content Technology and its Applications, 2011, 5 (01) : 87 - 94
  • [25] Scalable, password-based and threshold authentication for smart homes
    Andrea Huszti
    Szabolcs Kovács
    Norbert Oláh
    International Journal of Information Security, 2022, 21 : 707 - 723
  • [26] A Novel Multi-server Environment Authentication Protocol
    Li Haixia
    Lu Chuiwei
    Sun Sheng
    PROCESSING OF 2014 INTERNATIONAL CONFERENCE ON MULTISENSOR FUSION AND INFORMATION INTEGRATION FOR INTELLIGENT SYSTEMS (MFI), 2014,
  • [27] Threshold password-based authentication using bilinear pairings
    Lee, S
    Han, K
    Kang, SK
    Kim, K
    Ine, SR
    PUBLIC KEY INFRASTRUCTURE, PROCEEDINGS, 2004, 3093 : 350 - 363
  • [28] An enhanced multi-server authentication protocol using password and smart-card: cryptanalysis and design
    Maitra, Tanmoy
    Islam, S. K. Hafizul
    Amin, Ruhul
    Giri, Debasis
    Khan, Muhammad Khurram
    Kumar, Neeraj
    SECURITY AND COMMUNICATION NETWORKS, 2016, 9 (17) : 4615 - 4638
  • [29] Password-based independent authentication and key exchange protocol
    Jung, KS
    Kim, JY
    Chung, TC
    ICICS-PCM 2003, VOLS 1-3, PROCEEDINGS, 2003, : 1908 - 1912
  • [30] An Efficient Biometric and Password-Based Remote User Authentication using Smart Card for Telecare Medical Information Systems in Multi-Server Environment
    Tanmoy Maitra
    Debasis Giri
    Journal of Medical Systems, 2014, 38