A Threshold Multi-Server Protocol for Password-Based Authentication

被引:3
|
作者
Guan, Mengxiang [1 ]
Song, Jiaxing [1 ]
Liu, Weidong [1 ]
机构
[1] Tsinghua Univ, Dept CST, Beijing, Peoples R China
关键词
security; password; authenication;
D O I
10.1109/CSCloud.2016.26
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Password-based user authentication service is widely used in Internet. Most of the password-based authentication protocols are constructed under the single-server structure that a authencitation server stores cleartext passwords or verification data derived from password and responds to users' authentication request. The security of single-server authentication system is very fragile. In particular, when the server is comprimised, all of users' verification data is exposed to the attacker. Nowadays, development of mobile Internet leads the demand of authentication on roaming device. In this scenario, easily memorable short password and simple secret is accepted by most people despite of its security limitation. The utilization of short password worsens the situation of single-server authentication protocol. Attackers controlling the system can launch off-line dictionary attack from internal of server side to obtain users' original password. Multi-server authentication protocols can improve the security of verification data by distributed storing data on the cluster. This approach increases the difficulty of internal attack and guarantees security even if a portion of servers in the cluster are controlled by adversary. But in practice, There are some problems in existing multi-server protocols. For example, communicating with multiple servers brings extra network and computational burden to client device. To address these problems, in this paper we propose a novel password-based multi-server authenication protocol which not only require less computation on client device but remain functional and secure even if adversary controls some servers and forces them collude to attack our protocol.
引用
收藏
页码:108 / 118
页数:11
相关论文
共 50 条
  • [41] A lightweight password-based authentication protocol using smart card
    Wang, Chenyu
    Wang, Ding
    Xu, Guoai
    Guo, Yanhui
    INTERNATIONAL JOURNAL OF COMMUNICATION SYSTEMS, 2017, 30 (16)
  • [42] An Improvement Password-based Authentication Protocol Using Smart Card
    Hui, Liu
    SENSORS, MEASUREMENT AND INTELLIGENT MATERIALS, PTS 1-4, 2013, 303-306 : 2182 - 2185
  • [43] A smart card-based remote scheme for password authentication in multi-server Internet services
    Tsaur, WJ
    Wu, CC
    Lee, WB
    COMPUTER STANDARDS & INTERFACES, 2004, 27 (01) : 39 - 51
  • [44] An efficient and secure multi-server password authentication scheme using smart cards
    Chang, CC
    Lee, JS
    2004 INTERNATIONAL CONFERENCE ON CYBERWORLDS, PROCEEDINGS, 2004, : 417 - 422
  • [45] Cryptanalysis of Tan's improvement on a password authentication scheme for multi-server environments
    Feng, Tung-Huang
    Ling, Chung-Huei
    Hwang, Min-Shiang
    International Journal of Network Security, 2014, 16 (04) : 318 - 321
  • [46] A secure remote password authentication scheme with key agreement for multi-server environments
    Lee, Wei-Bin
    Wu, Chia-Chun
    Tsaur, Woei-Jiunn
    WMSCI 2005: 9th World Multi-Conference on Systemics, Cybernetics and Informatics, Vol 5, 2005, : 19 - 23
  • [47] An efficient and secure multi-server password authentication scheme using smart cards
    Chang, C.-C. (ccc@cs.ccu.edu.tw), (IEEE Computer Society):
  • [48] An improved authentication protocol-based dynamic identity for multi-server environments
    Cui, Jianming
    Zhang, Xiaojun
    Cao, Ning
    Zhang, Dexue
    Ding, Jianrui
    Li, Guofu
    INTERNATIONAL JOURNAL OF DISTRIBUTED SENSOR NETWORKS, 2018, 14 (05):
  • [49] Quantum-Resistant Password-Based Threshold Single-Sign-On Authentication with Updatable Server Private Key
    Jiang, Jingwei
    Wang, Ding
    Zhang, Guoyin
    Chen, Zhiyuan
    COMPUTER SECURITY - ESORICS 2022, PT II, 2022, 13555 : 295 - 316
  • [50] A Novel Multi-server based Authentication Scheme
    Yeh, Kuo-Hui
    2014 INTERNATIONAL CONFERENCE ON INFORMATION SCIENCE, ELECTRONICS AND ELECTRICAL ENGINEERING (ISEEE), VOLS 1-3, 2014, : 2020 - 2024