UC-secure Two-Server Password-Based Authentication Protocol and Its Applications

被引:5
|
作者
Zhang, Lin [1 ]
Zhang, Zhenfeng [1 ]
Hu, Xuexian [2 ]
机构
[1] Chinese Acad Sci, Inst Software, Trusted Comp & Informat Assurance Lab, Beijing, Peoples R China
[2] State Key Lab Math Engn & Adv Comp, Zhengzhou, Peoples R China
关键词
Universal composability; two-server password-based authentication; key exchange; secret sharing;
D O I
10.1145/2897845.2897872
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
A two-server password-based authentication (2PA) protocol is a special kind of authentication primitive that provides additional protection for the user's password. Through a 2PA protocol, a user can distribute his low-entropy password between two authentication servers in the initialization phase and authenticate himself merely via a matching password in the login phase. No single server can learn any information about the user's password, nor impersonate the legitimate user to authenticate to the honest server. In this paper, we first formulate and realize the security definition of two-server password-based authentication in the well-known universal composability (UC) framework, which thus provides desirable properties such as composable security. We show that our construction is suitable for the asymmetric communication model in which one server acts as the front-end server interacting directly with the user and the other stays backstage. Then, we show that our protocol could be easily extended to more complicate password-based cryptographic protocols such as two-server password-authenticated key exchange (2PAKE) and two-server password-authenticated secret sharing (2PASS), which enjoy stronger security guarantees and better efficiency performances in comparison with the existing schemes
引用
收藏
页码:153 / 164
页数:12
相关论文
共 50 条
  • [21] A New Password-Based Multi-server Authentication Scheme Robust to Password Guessing Attacks
    Jia-Lun Tsai
    Nai-Wei Lo
    Tzong-Chen Wu
    Wireless Personal Communications, 2013, 71 : 1977 - 1988
  • [22] A lightweight password-based authentication protocol using smart card
    Wang, Chenyu
    Wang, Ding
    Xu, Guoai
    Guo, Yanhui
    INTERNATIONAL JOURNAL OF COMMUNICATION SYSTEMS, 2017, 30 (16)
  • [23] Efficient and secure password-based authentication protocols against guessing attacks
    Kwon, T
    Song, J
    COMPUTER COMMUNICATIONS, 1998, 21 (09) : 853 - 861
  • [24] Efficient Password-Based Authenticated Key Exchange Protocol in the UC Framework
    Hu, Xuexian
    Liu, Wenfen
    INFORMATION SECURITY AND CRYPTOLOGY, 2010, 6151 : 144 - 153
  • [25] An Improvement Password-based Authentication Protocol Using Smart Card
    Hui, Liu
    SENSORS, MEASUREMENT AND INTELLIGENT MATERIALS, PTS 1-4, 2013, 303-306 : 2182 - 2185
  • [26] An Efficient Two-Server Password-only User Authentication for Consumer Electronic Devices
    Odelu, Vanga
    2019 IEEE INTERNATIONAL CONFERENCE ON CONSUMER ELECTRONICS (ICCE), 2019,
  • [27] A New Password-Based Multi-server Authentication Scheme Robust to Password Guessing Attacks
    Tsai, Jia-Lun
    Lo, Nai-Wei
    Wu, Tzong-Chen
    WIRELESS PERSONAL COMMUNICATIONS, 2013, 71 (03) : 1977 - 1988
  • [28] Efficient and secure password-based authentication protocols against guessing attacks
    Yonsei Univ, Seoul, Korea, Republic of
    Comput Commun, 9 (853-861):
  • [29] Efficient and secure password-based authenticated key exchange protocol
    Wu, Shuhua
    Zhu, Yuefei
    2006 INTERNATIONAL CONFERENCE ON COMPUTATIONAL INTELLIGENCE AND SECURITY, PTS 1 AND 2, PROCEEDINGS, 2006, : 1269 - 1272
  • [30] Security analysis of a password-based authentication protocol proposed to IEEE 1363
    Zhao, Z
    Dong, ZQ
    Wang, YG
    THEORETICAL COMPUTER SCIENCE, 2006, 352 (1-3) : 280 - 287