DocumentCode
1699562
Title
Password Protected Credentials
Author
Yang, Yanjiang ; Bao, Feng
Author_Institution
Inst. for Infocomm Res., Singapore, Singapore
fYear
2010
Firstpage
541
Lastpage
545
Abstract
Password authentication is a widely used entity authentication means nowadays. In password authentication, the server needs to manage a password file containing all user passwords. This poses a tremendous threat to the safety of the passwords: if the server is compromised, all passwords are immediately disclosed. A common countermeasure to this issue of single point of failure is to deploy multiple servers for secret-sharing of the passwords. In this work, we propose an alternative approach to mitigate this issue, which does not require the deployment of multiple servers. The basic idea of our approach is that the server issues to each user a credential for authentication, and the users protect theircredentials using passwords. A crucial feature is that thepassword-protected credentials do not require secure devices for storage, thus any personal portable device can used to carry a user´s password-protected credential. This arguably retains portability of passwords. We present a concrete scheme to instantiate our approach, which is shown to be secure against off-line guessing attacks under the DDH assumption.
Keywords
message authentication; DDH assumption; failure point; multiple server; password authentication; password portability; password protected credential; secret sharing; Authentication; Computers; Protocols; Public key; Servers; authentication credential; guessing attack; password authentication; single point of failure;
fLanguage
English
Publisher
ieee
Conference_Titel
Multimedia Information Networking and Security (MINES), 2010 International Conference on
Conference_Location
Nanjing, Jiangsu
Print_ISBN
978-1-4244-8626-7
Electronic_ISBN
978-0-7695-4258-4
Type
conf
DOI
10.1109/MINES.2010.120
Filename
5670871
Link To Document