Strong Authentication without Temper-Resistant Hardware and Application to Federated Identities
Zhenfeng Zhang, Yuchen Wang, Kang Yang
摘要
Shared credential is currently the most widespread form of end user authentication with its convenience, but it is also criticized for being vulnerable to credential database theft and phishing attacks. While several alternative mechanisms are proposed to offer strong authentication with cryptographic challenge-response protocols, they are cumbersome to use due to the need of tamper-resistant hardware modules at user end. In this paper, we propose the first strong authentication mechanism without the reliance on tamper-resistant hardware at user end. A user authenticates with a password-based credential via generating designated-verifiable authentication tokens. Our scheme is resistant to offline dictionary attacks in spite that the attacker can steal the password-protected credentials, and thus can be implemented on general-purpose devices. More specifically, we first introduce and formalize the notion of Password-Based Credential (PBC), which models the resistance of offline attacks and the unforageability of authentication tokens even if attackers can see authentication tokens and capture password-wrapped credentials of honest users. We then present a highly-efficient construction of PBC using a "randomize-thenprove" approach, and prove its security. The construction does not involve bilinear-pairings, and can be implemented with common cryptographic libraries for many platforms. We also present a technique to transform the PBC scheme to be publiclyverifiable, and present an application of PBC in federated identity systems to provide holder-of-key assertion mechanisms. Compared with current certificate-based approaches, it is more convenient and user-friendly, and can be used with the federation systems that employ privacy-preserving measures (e.g., Sign-in with Apple). We also implement the PBC scheme and evaluate its performance for different applications over various network environment. When PBC is used as a strong authentication mechanism for end users, it saves 26%-36% of time than the approach based on ECDSA with a tamper-resistant hardware module. As for its application in federation, it could even save more time when the user proves its possession of key to a Relying Party.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper1
问问它们各自怎么用它它引用的顶会 Paper5
- Practical UC-Secure Delegatable Credentials with Attributes and Their Application to BlockchainJan Camenisch, Manu Drijvers, Maria DubovitskayaCCS 2017 · 被引用 76 次
- Phoenix: Rebirth of a Cryptographic Password-Hardening ServiceRussell W. F. Lai, Christoph Egger, Dominique Schröder, Sherman S. M. ChowUSENIX Security 2017 · 被引用 45 次
- T/Key: Second-Factor Authentication From Secure Hash ChainsDmitry Kogan, Nathan Manohar, Dan BonehCCS 2017 · 被引用 44 次
- Practical Anonymous Password Authentication and TLS with Anonymous Client AuthenticationZhenfeng Zhang, Kang Yang, Xuexian Hu, Yuchen WangCCS 2016 · 被引用 36 次
- Efficient Cryptographic Password Hardening Services from Partially Oblivious CommitmentsJonas Schneider, Nils Fleischhacker, Dominique Schröder, Michael BackesCCS 2016 · 被引用 30 次
相关 Paper
- How to Bind Anonymous Credentials to HumansJulia Hesse, Nitin Singh, Alessandro SorniottiUSENIX Security 2023
- PASTA: PASsword-based Threshold AuthenticationShashank Agrawal, Peihan Miao, Payman Mohassel, Pratyay MukherjeeCCS 2018 · 被引用 84 次
- With a Little Help from My Friends: Constructing Practical Anonymous CredentialsLucjan Hanzlik, Daniel SlamanigCCS 2021 · 被引用 52 次
- Do You Need a Receipt? Anonymous Credential Revocation at Continental Scale via Private Record CertificationKasra EdalatNejad, Sebastian Faust, Jonas Hofmann, Philipp-Florens Lehwalder 等USENIX Security 2026 · 被引用 1 次
- Device-Bound Anonymous Credentials With(out) Trusted HardwareKarla Friedrichs, Franklin Harding, Anja Lehmann, Anna LysyanskayaEUROCRYPT 2026 · 被引用 1 次
