MPCAuth: Multi-factor Authentication for Distributed-trust Systems
Sijun Tan, Weikeng Chen, Ryan Deng, Raluca Ada Popa
摘要
Systems with distributed trust have attracted growing research attention and seen increasing industry adoptions. In these systems, critical secrets are distributed across N servers, and computations are performed privately using secure multi-party computation (SMPC). Authentication for these distributed-trust systems faces two challenges. The first challenge is ease-of-use. Namely, how can an authentication protocol maintain its user experience without sacrificing security? To avoid a central point of attack, a client needs to authenticate to each server separately. However, this would require the client to authenticate N times for each authentication factor, which greatly hampers usability. The second challenge is privacy, as the client’s sensitive profiles are now exposed to all N servers under different trust domains, which creates N times the attack surface for the profile data.We present MPCAuth, a multi-factor authentication system for distributed-trust applications that address both challenges. Our system enables a client to authenticate to N servers independently with the work of only one authentication. In addition, our system is profile hiding, meaning that the client’s authentication profiles such as her email username, phone number, passwords, and biometric features are not revealed unless all servers are compromised. We propose secure and practical protocols for an array of widely adopted authentication factors, including email passcodes, SMS messages, U2F, security questions/passwords, and biometrics. Our system finds practical applications in the space of cryptocurrency custody and collaborative machine learning, and benefits future adoptions of distributed-trust applications.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- Secure Account Recovery for a Privacy-Preserving Web ServiceRyan Little, Lucy Qin, Mayank VariaUSENIX Security 2024 · 被引用 7 次
- Flock: A Framework for Deploying On-Demand Distributed TrustDarya Kaviani, Sijun Tan, Pravein Govindan Kannan, Raluca Ada PopaOSDI 2024 · 被引用 5 次
- Stealing Trust: Unraveling Blind Message Attacks in Web3 AuthenticationKailun Yan, Xiaokuan Zhang, Wenrui DiaoCCS 2024 · 被引用 5 次
- PrivAGM: Secure Construction of Differentially Private Directed Attributed Graph Models on Decentralized Social GraphsSonglei Wang, Yifeng Zheng, Xiaohua Jia, Haibo HuVLDB 2025 · 被引用 3 次
- DiStefano: Decentralized Infrastructure for Sharing Trusted Encrypted Facts and Nothing MoreSofía Celi, Alex Davidson, Hamed Haddadi, Gonçalo Pestana 等NDSS 2025
它引用的顶会 Paper15
- MASCOT: Faster Malicious Arithmetic Secure Computation with Oblivious TransferMarcel Keller, Emmanuela Orsini, Peter SchollCCS 2016 · 被引用 487 次
- Verified Models and Reference Implementations for the TLS 1.3 Standard CandidateKarthikeyan Bhargavan, Bruno Blanchet, Nadim KobeissiS&P 2017 · 被引用 233 次
- Scaling ORAM for Secure ComputationJack Doerner, Abhi ShelatCCS 2017 · 被引用 221 次
- Global-Scale Secure Multiparty ComputationXiao Wang, Samuel Ranellucci, Jonathan KatzCCS 2017 · 被引用 220 次
- Zero-Knowledge Contingent Payments Revisited: Attacks and Payments for ServicesMatteo Campanelli, Rosario Gennaro, Steven Goldfeder, Luca NizzardoCCS 2017 · 被引用 170 次
相关 Paper
- Asynchronous AuthenticationMarwa Mouallem, Ittay EyalCCS 2024 · 被引用 1 次
- Scalable and Privacy-Preserving Federated Principal Component AnalysisDavid Froelicher, Hyunghoon Cho, Manaswitha Edupalli, Joao Sa Sousa 等S&P 2023
- An End-to-End System for Large Scale P2P MPC-as-a-Service and Low-Bandwidth MPC for Weak ParticipantsAssi Barak, Martin Hirt, Lior Koskas, Yehuda LindellCCS 2018 · 被引用 52 次
- CryptGNN: Enabling Secure Inference for Graph Neural NetworksPritam Sen, Yao Ma, Cristian BorceaCCS 2025
- Practical Key-Extraction Attacks in Leading MPC WalletsNikolaos Makriyannis, Oren Yomtov, Arik GalanskyCCS 2024 · 被引用 2 次
