• DocumentCode
    932460
  • Title

    A practical password-based two-server authentication and key exchange system

  • Author

    Yang, Yanjiang ; Deng, Robert H. ; Bao, Feng

  • Author_Institution
    Sch. of Inf. Syst., Singapore Manage. Univ.
  • Volume
    3
  • Issue
    2
  • fYear
    2006
  • Firstpage
    105
  • Lastpage
    114
  • Abstract
    Most password-based user authentication systems place total trust on the authentication server where cleartext passwords or easily derived password verification data are stored in a central database. Such systems are, thus, by no means resilient against offline dictionary attacks initiated at the server side. Compromise of the authentication server by either outsiders or insiders subjects all user passwords to exposure and may have serious legal and financial repercussions to an organization. Recently, several multiserver password systems were proposed to circumvent the single point of vulnerability inherent in the single-server architecture. However, these multiserver systems are difficult to deploy and operate in practice since either a user has to communicate simultaneously with multiple servers or the protocols are quite expensive. In this paper, we present a practical password-based user authentication and key exchange system employing a novel two-server architecture. Our system has a number of appealing features. In our system, only a front-end service server engages directly with users while a control server stays behind the scene; therefore, it can be directly applied to strengthen existing single-server password systems. In addition, the system is secure against offline dictionary attacks mounted by either of the two servers
  • Keywords
    authorisation; computer networks; cryptography; network servers; telecommunication security; authentication server; cleartext passwords; control server; front-end service server; key exchange system; multiserver password systems; offline dictionary attacks; password verification data; password-based two-server authentication; password-based user authentication systems; single-server password systems; Authentication; Biometrics; Databases; Dictionaries; Digital signatures; Hardware; Law; Public key; Public key cryptography; Software safety; Password system; key exchange; offline dictionary attack.; password verification data (PVD); user authentication;
  • fLanguage
    English
  • Journal_Title
    Dependable and Secure Computing, IEEE Transactions on
  • Publisher
    ieee
  • ISSN
    1545-5971
  • Type

    jour

  • DOI
    10.1109/TDSC.2006.16
  • Filename
    1632005