Title
Password-based authentication and key distribution protocols with perfect forward secrecy
Abstract
In an open networking environment, a workstation usually needs to identify its legal users for providing its services. Kerberos provides an efficient approach whereby a trusted third-party authentication server is used to verify users' identities. However, Kerberos enforces the user to use strong cryptographic secret for user authentication, and hence is insecure from password guessing attacks if the user uses a weak password for convenience. In this paper, we focus on such an environment in which the users can use easy-to-remember passwords. In addition to password guessing attacks, perfect forward secrecy (PFS in short) is another important security consideration when designing an authentication and key distribution protocol. Based on the capability of protecting the client's password, the application server's secret key, and the authentication server's private key, we define seven classes of perfect forward secrecy and focus on protocols achieving class-1, class-3, and class-7 due to their hierarchical relations. Then, we propose three secure authentication and key distribution protocols to provide perfect forward secrecy of these three classes. All these protocols are efficient in protecting poorly-chosen passwords chosen by users from guessing attacks and replay attacks.
Year
DOI
Venue
2006
10.1016/j.jcss.2006.03.005
J. Comput. Syst. Sci.
Keywords
Field
DocType
poorly-chosen password,third-party authentication server,key distribution protocol,perfect forward secrecy,password,secret key,easy-to-remember password,network security,private key,authentication,user authentication,guessing attack,secure authentication,authentication server,password-based authentication,key distribution,trusted third party
Password strength,Authentication server,Computer security,Challenge–response authentication,S/KEY,One-time password,Password policy,Password,Cognitive password,Mathematics
Journal
Volume
Issue
ISSN
72
6
Journal of Computer and System Sciences
Citations 
PageRank 
References 
7
0.86
13
Authors
2
Name
Order
Citations
PageRank
Hung-min Sun1134397.06
Her-Tyan Yeh2787.63