PASTA: PASsword-based Threshold Authentication
Shashank Agrawal, Peihan Miao, Payman Mohassel, Pratyay Mukherjee
Abstract
Token-based authentication is commonly used to enable a single-sign-on experience on the web, in mobile applications and on enterprise networks using a wide range of open standards and network authentication protocols: clients sign on to an identity provider using their username/password to obtain a cryptographic token generated with a master secret key, and store the token for future accesses to various services and applications. The authentication server(s) are single point of failures that if breached, enable attackers to forge arbitrary tokens or mount offline dictionary attacks to recover client credentials. Our work is the first to introduce and formalize the notion of password-based threshold token-based authentication which distributes the role of an identity provider among n servers. Any t servers can collectively verify passwords and generate tokens, while no t-1 servers can forge a valid token or mount offline dictionary attacks. We then introduce PASTA, a general framework that can be instantiated using any threshold token generation scheme, wherein clients can "sign-on" using a two-round (optimal) protocol that meets our strong notions of unforgeability and password-safety. We instantiate and implement our framework in C++ using two threshold message authentication codes (MAC) and two threshold digital signatures with different trade-offs. Our experiments show that the overhead of protecting secrets and credentials against breaches in PASTA, i.e. compared to a naive single server solution, is extremely low (1-5%) in the most likely setting where client and servers communicate over the internet. The overhead is higher in case of MAC-based tokens over a LAN (though still only a few milliseconds) due to public-key operations in PASTA. We show, however, that this cost is inherent by proving a symmetric-key only solution impossible.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 136c08ed-c4a4-4ca4-ab54-986ca3636b4bCited by top-tier papers6
- How to Attack and Generate HoneywordsDing Wang, Yunkai Zou, Qiying Dong, Yuanming Song et al.S&P 2022 · 45 citations
- Threshold Password-Hardened Encryption ServicesJulian Brost, Christoph Egger, Russell W. F. Lai, Fritz Schmid et al.CCS 2020 · 24 citations
- FlexiRand: Output Private (Distributed) VRFs and Application to BlockchainsAniket Kate, Easwar Vivek Mangipudi, Siva Maradana, Pratyay MukherjeeCCS 2023 · 11 citations
- Maginot Line: Assessing a New Cross-app Threat to PII-as-Factor Authentication in Chinese Mobile AppsFannv He, Yan Jia, Jiayu Zhao, Yue Fang et al.NDSS 2024
- Amortized Threshold Symmetric-key EncryptionMihai Christodorescu, Sivanarayana Gaddam, Pratyay Mukherjee, Rohit SinhaCCS 2021
Related papers
- Strong Authentication without Temper-Resistant Hardware and Application to Federated IdentitiesZhenfeng Zhang, Yuchen Wang, Kang YangNDSS 2020
- Multi-Factor Key Derivation Function (MFKDF) for Fast, Flexible, Secure, & Practical Key ManagementVivek Nair, Dawn SongUSENIX Security 2023
- Groundhog: A Restart-Based Systems Framework for Increasing Availability in Threshold CryptosystemsAshish Kashinath, Disha Agarwala, Gabriel Kulp, Sourav Das et al.S&P 2025
- Authenticated Network Time SynchronizationBenjamin Dowling, Douglas Stebila, Greg ZaveruchaUSENIX Security 2016 · 35 citations
- T/Key: Second-Factor Authentication From Secure Hash ChainsDmitry Kogan, Nathan Manohar, Dan BonehCCS 2017 · 44 citations
