USENIX Security2023Top-tier venue
Multi-Factor Key Derivation Function (MFKDF) for Fast, Flexible, Secure, & Practical Key Management
Vivek Nair, Dawn Song
Abstract
We present the first general construction of a Multi-Factor Key Derivation Function (MFKDF). Our function expands upon password-based key derivation functions (PBKDFs) with support for using other popular authentication factors like TOTP, HOTP, and hardware tokens in the key derivation process. In doing so, it provides an exponential security improvement over PBKDFs with less than 12 ms of additional computational overhead in a typical web browser. We further present a threshold MFKDF construction, allowing for client-side key recovery and reconstitution if a factor is lost. Finally, by "stacking" derived keys, we provide a means of cryptographically enforcing arbitrarily specific key derivation policies. The result is a paradigm shift toward direct cryptographic protection of user data using all available authentication factors, with no noticeable change to the user experience. We demonstrate the ability of our solution to not only significantly improve the security of existing systems implementing PBKDFs, but also to enable new applications where PBKDFs would not be considered a feasible approach.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 4f397cbf-e644-42a6-9b57-5aa56a062c2aCited by top-tier papers3
- "I Can't Believe It's Not Custodial!": Usable Trustless Decentralized Key ManagementTanusree Sharma, Vivek C. Nair, Henry Wang, Yang Wang et al.CHI 2024 · 6 citations
- MFKDF: Multiple Factors Knocked Down FlatMatteo Scarlata, Matilda Backendal, Miro HallerUSENIX Security 2024 · 3 citations
- Anchor-DKG: Distributed Key Generation with Repeating PartiesHanwen Feng, Qiang Tang, Sri AravindaKrishnan ThyagarajanCCS 2026
Related papers
- "We've Disabled MFA for You": An Evaluation of the Security and Usability of Multi-Factor Authentication Recovery DeploymentsSabrina Amft, Sandra Höltervennhoff, Nicolas Huaman, Alexander Krause et al.CCS 2023 · 14 citations
- T/Key: Second-Factor Authentication From Secure Hash ChainsDmitry Kogan, Nathan Manohar, Dan BonehCCS 2017 · 44 citations
- True2F: Backdoor-Resistant Authentication TokensEmma Dauterman, Henry Corrigan-Gibbs, David Mazières, Dan Boneh et al.S&P 2019 · 24 citations
- Security and Privacy Failures in Popular 2FA AppsConor Gilsenan, Fuzail Shakir, Noura Alomar, Serge EgelmanUSENIX Security 2023
- Security of Streaming Encryption in Google's Tink LibraryViet Tung Hoang, Yaobin ShenCCS 2020
