The Experts below are selected from a list of 11715 Experts worldwide ranked by ideXlab platform
Erika Linzner - One of the best experts on this subject based on the ideXlab platform.
-
research guides academic technology launchpad Password policy
2013Co-Authors: Erika LinznerAbstract:Quick Guide to computer and academic technology resources for students. Password Information and policies for college accounts
Jennifer Kasch - One of the best experts on this subject based on the ideXlab platform.
-
research guides academic technology launchpad Password policy
2013Co-Authors: Jennifer KaschAbstract:Computer and academic technology resources for students Password Information and policies for college accounts
Virgil D Gligor - One of the best experts on this subject based on the ideXlab platform.
-
two server Password only authenticated key exchange
Journal of Computer and System Sciences, 2012Co-Authors: Jonathan Katz, Philip Mackenzie, Gelareh Taban, Virgil D GligorAbstract:Typical protocols for Password-based authentication assume a single server that stores all the Information (e.g., the Password) necessary to authenticate a user. An inherent limitation of this approach, assuming low-entropy Passwords are used, is that the user@?s Password is exposed if this server is ever compromised. To address this issue, it has been suggested to share a user@?s Password Information among multiple servers, and to have these servers cooperate (possibly in a threshold manner) when the user wants to authenticate. We show here a two-server version of the Password-only key-exchange protocol of Katz, Ostrovsky, and Yung (the KOY protocol). Our work gives the first secure two-server protocol for the Password-only setting (in which the user need remember only a Password, and not the servers@? public keys), and is the first two-server protocol (in any setting) with a proof of security in the standard model. Our work thus fills a gap left by the work of MacKenzie et al. (2006) [31] and Di Raimondo and Gennaro (2006) [16]. As an additional benefit of our work, we show modifications that improve the efficiency of the original KOY protocol.
-
two server Password only authenticated key exchange
Applied Cryptography and Network Security, 2005Co-Authors: Jonathan Katz, Philip Mackenzie, Gelareh Taban, Virgil D GligorAbstract:Typical protocols for Password-based authentication assume a single server which stores all the Information (e.g.), the Password necessary to authenticate a user. Unfortunately, an inherent limitation of this approach (assuming low-entropy Passwords are used) is that the user's Password is exposed if this server is ever compromised. To address this issue, a number of schemes have been proposed in which a user's Password Information is shared among multiple servers, and these servers cooperate in a threshold manner when the user wants to authenticate. We show here a two-server protocol for this task assuming public parameters available to everyone in the system (as well as the adversary). Ours is the first provably-secure two-server protocol for the important Password-only setting (in which the user need remember only a Password, and not the servers' public keys), and is the first two-server protocol (in any setting) with a proof of security in the standard model.
Philip Mackenzie - One of the best experts on this subject based on the ideXlab platform.
-
two server Password only authenticated key exchange
Journal of Computer and System Sciences, 2012Co-Authors: Jonathan Katz, Philip Mackenzie, Gelareh Taban, Virgil D GligorAbstract:Typical protocols for Password-based authentication assume a single server that stores all the Information (e.g., the Password) necessary to authenticate a user. An inherent limitation of this approach, assuming low-entropy Passwords are used, is that the user@?s Password is exposed if this server is ever compromised. To address this issue, it has been suggested to share a user@?s Password Information among multiple servers, and to have these servers cooperate (possibly in a threshold manner) when the user wants to authenticate. We show here a two-server version of the Password-only key-exchange protocol of Katz, Ostrovsky, and Yung (the KOY protocol). Our work gives the first secure two-server protocol for the Password-only setting (in which the user need remember only a Password, and not the servers@? public keys), and is the first two-server protocol (in any setting) with a proof of security in the standard model. Our work thus fills a gap left by the work of MacKenzie et al. (2006) [31] and Di Raimondo and Gennaro (2006) [16]. As an additional benefit of our work, we show modifications that improve the efficiency of the original KOY protocol.
-
two server Password only authenticated key exchange
Applied Cryptography and Network Security, 2005Co-Authors: Jonathan Katz, Philip Mackenzie, Gelareh Taban, Virgil D GligorAbstract:Typical protocols for Password-based authentication assume a single server which stores all the Information (e.g.), the Password necessary to authenticate a user. Unfortunately, an inherent limitation of this approach (assuming low-entropy Passwords are used) is that the user's Password is exposed if this server is ever compromised. To address this issue, a number of schemes have been proposed in which a user's Password Information is shared among multiple servers, and these servers cooperate in a threshold manner when the user wants to authenticate. We show here a two-server protocol for this task assuming public parameters available to everyone in the system (as well as the adversary). Ours is the first provably-secure two-server protocol for the important Password-only setting (in which the user need remember only a Password, and not the servers' public keys), and is the first two-server protocol (in any setting) with a proof of security in the standard model.
-
Provably Secure
Springer-Verlag, 2000Co-Authors: Password-authenticated Key Exchange, Philip Mackenzie, Victor Boyko, Sarvar PatelAbstract:When designing Password-authenticated key exchange protocols (as opposed to key exchange protocols authenticated using cryptographically secure keys), one must not allow any Information to be leaked that would allow verification of the Password (a weak shared key), since an attacker who obtains this Information may be able to run an off-line dictionary attack to determine the correct Password. Of course, it may be extremely difficult to hide all Password Information, especially if the attacker may pose as one of the parties in the key exchange. Nevertheless, we present a new protocol called PAK which is the first Diffie-Hellman-based Password-authenticated key exchange protocol to provide a formal proof of security (in the random oracle model) against both passive and active adversaries. In addition to the PAK protocol that provides mutual explicit authentication, we also show a more efficient protocol called PPK that is provably secure in the implicit-authentication model. We then extend PAK to a protocol called PAK-X, in which one side (the client) stores a plaintext version of the Password, while the other side (the server) only stores a verifier for the Password. We formally prove security of PAK-X, even when the server is compromised. Our formal model for Password-authenticated key exchange is new, and may be of independent interest
Jonathan Katz - One of the best experts on this subject based on the ideXlab platform.
-
two server Password only authenticated key exchange
Journal of Computer and System Sciences, 2012Co-Authors: Jonathan Katz, Philip Mackenzie, Gelareh Taban, Virgil D GligorAbstract:Typical protocols for Password-based authentication assume a single server that stores all the Information (e.g., the Password) necessary to authenticate a user. An inherent limitation of this approach, assuming low-entropy Passwords are used, is that the user@?s Password is exposed if this server is ever compromised. To address this issue, it has been suggested to share a user@?s Password Information among multiple servers, and to have these servers cooperate (possibly in a threshold manner) when the user wants to authenticate. We show here a two-server version of the Password-only key-exchange protocol of Katz, Ostrovsky, and Yung (the KOY protocol). Our work gives the first secure two-server protocol for the Password-only setting (in which the user need remember only a Password, and not the servers@? public keys), and is the first two-server protocol (in any setting) with a proof of security in the standard model. Our work thus fills a gap left by the work of MacKenzie et al. (2006) [31] and Di Raimondo and Gennaro (2006) [16]. As an additional benefit of our work, we show modifications that improve the efficiency of the original KOY protocol.
-
two server Password only authenticated key exchange
Applied Cryptography and Network Security, 2005Co-Authors: Jonathan Katz, Philip Mackenzie, Gelareh Taban, Virgil D GligorAbstract:Typical protocols for Password-based authentication assume a single server which stores all the Information (e.g.), the Password necessary to authenticate a user. Unfortunately, an inherent limitation of this approach (assuming low-entropy Passwords are used) is that the user's Password is exposed if this server is ever compromised. To address this issue, a number of schemes have been proposed in which a user's Password Information is shared among multiple servers, and these servers cooperate in a threshold manner when the user wants to authenticate. We show here a two-server protocol for this task assuming public parameters available to everyone in the system (as well as the adversary). Ours is the first provably-secure two-server protocol for the important Password-only setting (in which the user need remember only a Password, and not the servers' public keys), and is the first two-server protocol (in any setting) with a proof of security in the standard model.