Multi-Factor Key Derivation Function (MFKDF) for Fast, Flexible, Secure, & Practical Key Management
Vivek Nair, Dawn Song
摘要
We present the first general construction of a Multi-Factor Key Derivation Function (MFKDF). Our function expands upon password-based key derivation functions (PBKDFs) with support for using other popular authentication factors like TOTP, HOTP, and hardware tokens in the key derivation process. In doing so, it provides an exponential security improvement over PBKDFs with less than 12 ms of additional computational overhead in a typical web browser. We further present a threshold MFKDF construction, allowing for client-side key recovery and reconstitution if a factor is lost. Finally, by "stacking" derived keys, we provide a means of cryptographically enforcing arbitrarily specific key derivation policies. The result is a paradigm shift toward direct cryptographic protection of user data using all available authentication factors, with no noticeable change to the user experience. We demonstrate the ability of our solution to not only significantly improve the security of existing systems implementing PBKDFs, but also to enable new applications where PBKDFs would not be considered a feasible approach.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- "I Can't Believe It's Not Custodial!": Usable Trustless Decentralized Key ManagementTanusree Sharma, Vivek C. Nair, Henry Wang, Yang Wang 等CHI 2024 · 被引用 6 次
- MFKDF: Multiple Factors Knocked Down FlatMatteo Scarlata, Matilda Backendal, Miro HallerUSENIX Security 2024 · 被引用 3 次
- Anchor-DKG: Distributed Key Generation with Repeating PartiesHanwen Feng, Qiang Tang, Sri AravindaKrishnan ThyagarajanCCS 2026
相关 Paper
- "We've Disabled MFA for You": An Evaluation of the Security and Usability of Multi-Factor Authentication Recovery DeploymentsSabrina Amft, Sandra Höltervennhoff, Nicolas Huaman, Alexander Krause 等CCS 2023 · 被引用 14 次
- T/Key: Second-Factor Authentication From Secure Hash ChainsDmitry Kogan, Nathan Manohar, Dan BonehCCS 2017 · 被引用 44 次
- True2F: Backdoor-Resistant Authentication TokensEmma Dauterman, Henry Corrigan-Gibbs, David Mazières, Dan Boneh 等S&P 2019 · 被引用 24 次
- Security and Privacy Failures in Popular 2FA AppsConor Gilsenan, Fuzail Shakir, Noura Alomar, Serge EgelmanUSENIX Security 2023
- Security of Streaming Encryption in Google's Tink LibraryViet Tung Hoang, Yaobin ShenCCS 2020
