A Threshold Multi-Server Protocol for Password-Based Authentication

被引:3
|
作者
Guan, Mengxiang [1 ]
Song, Jiaxing [1 ]
Liu, Weidong [1 ]
机构
[1] Tsinghua Univ, Dept CST, Beijing, Peoples R China
关键词
security; password; authenication;
D O I
10.1109/CSCloud.2016.26
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Password-based user authentication service is widely used in Internet. Most of the password-based authentication protocols are constructed under the single-server structure that a authencitation server stores cleartext passwords or verification data derived from password and responds to users' authentication request. The security of single-server authentication system is very fragile. In particular, when the server is comprimised, all of users' verification data is exposed to the attacker. Nowadays, development of mobile Internet leads the demand of authentication on roaming device. In this scenario, easily memorable short password and simple secret is accepted by most people despite of its security limitation. The utilization of short password worsens the situation of single-server authentication protocol. Attackers controlling the system can launch off-line dictionary attack from internal of server side to obtain users' original password. Multi-server authentication protocols can improve the security of verification data by distributed storing data on the cluster. This approach increases the difficulty of internal attack and guarantees security even if a portion of servers in the cluster are controlled by adversary. But in practice, There are some problems in existing multi-server protocols. For example, communicating with multiple servers brings extra network and computational burden to client device. To address these problems, in this paper we propose a novel password-based multi-server authenication protocol which not only require less computation on client device but remain functional and secure even if adversary controls some servers and forces them collude to attack our protocol.
引用
收藏
页码:108 / 118
页数:11
相关论文
共 50 条
  • [31] Password-based user authentication protocol for mobile environment
    Moon, Sung-Won
    Kim, Young-Gab
    Moon, Chang-Joo
    Baik, Doo-Kwon
    Information Networking: ADVANCES IN DATA COMMUNICATIONS AND WIRELESS NETWORKS, 2006, 3961 : 743 - 753
  • [32] UC-secure Two-Server Password-Based Authentication Protocol and Its Applications
    Zhang, Lin
    Zhang, Zhenfeng
    Hu, Xuexian
    ASIA CCS'16: PROCEEDINGS OF THE 11TH ACM ASIA CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, 2016, : 153 - 164
  • [33] A Secure Anonymous Password-based Authentication Protocol with Control of Authentication Numbers
    Shin, SeongHan
    Kobara, Kazukuni
    PROCEEDINGS OF 2016 INTERNATIONAL SYMPOSIUM ON INFORMATION THEORY AND ITS APPLICATIONS (ISITA 2016), 2016, : 325 - 329
  • [34] An Efficient Biometric and Password-Based Remote User Authentication using Smart Card for Telecare Medical Information Systems in Multi-Server Environment
    Maitra, Tanmoy
    Giri, Debasis
    JOURNAL OF MEDICAL SYSTEMS, 2014, 38 (12)
  • [35] New multi-server password authentication scheme using neural networks
    Yoon, EJ
    Yoo, KY
    ADVANCES IN NATURAL COMPUTATION, PT 2, PROCEEDINGS, 2005, 3611 : 512 - 519
  • [36] Cryptanalysis and Improvement of a Biometrics-based Multi-server Authentication Protocol
    Gu, Yi
    Li, Shengqiang
    2018 INTERNATIONAL CONFERENCE ON COMPUTING, NETWORKING AND COMMUNICATIONS (ICNC), 2018, : 16 - 20
  • [37] Analysis and improvement of an authentication protocol for the multi-server architecture
    Wan, T. (wantao217@163.com), 2013, Science Press (40):
  • [38] A secure dynamic identity based authentication protocol for multi-server architecture
    Sood, Sandeep K.
    Sarje, Anil K.
    Singh, Kuldip
    JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2011, 34 (02) : 609 - 618
  • [39] Security analysis and improvement of the efficient password-based authentication protocol
    Kwon, T
    Park, YH
    Lee, HJ
    IEEE COMMUNICATIONS LETTERS, 2005, 9 (01) : 93 - 95
  • [40] Mitigating Server Breaches in Password-Based Authentication: Secure and Efficient Solutions
    Blazy, Olivier
    Chevalier, Celine
    Vergnaud, Damien
    TOPICS IN CRYPTOLOGY - CT-RSA 2016, 2016, 9610 : 3 - 18