Two-Factor Authentication Can Harden Servers Against Offline Password Search
Xavier Boyen, Stanislaw Jarecki, Phillip Nazarian, Jiayu Xu, Tianyu Zheng
摘要
We propose a novel notion of Two-Factor Authenticated Key Exchange (TFA-KE), defined in the universal composability model (UC), which extends asymmetric PAKE (aPAKE) by a 2nd authentication factor in the form of a -bit one-time code computed by a personal device based on a clock or counter. Our notion strengthens the security of standard integration of aPAKE with short authentication codes by additionally slowing down offline brute-force password search in case of server compromise by a factor of . In other words, our TFA-KE notion uses -bit authentication codes not only to improve on-line security of password authentication, as is the current practice, but also to strengthen password security on server corruption, whilst retaining the ability of aPAKE to avoid the common but deplorable practice of relying on "secure-channel" encryption for password protection.
We show a generic framework for implementing TFA-KE, with two efficient instantiations. Our key enabling tool is a tight one-way function (TOWF) with an algebraic structure that allows for its evaluation on a secret-shared input. We initiate the study of such functions, and we provide two proposals which we show to be tightly one-way in the Generic Group Model. Tightness means that a function evaluation on an input sampled from domain takes time to invert, which in our application implies that offline password search attacks are slowed to for passwords sampled from dictionary .
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
相关 Paper
- OneTwoPAKE: Two-Round Strong Asymmetric PAKE with Ideal SecurityYashvanth Kondi, Ian McQuoid, Kelsey Melissaris, Claudio Orlandi 等EUROCRYPT 2026 · 被引用 1 次
- Universally Composable Relaxed Password Authenticated Key ExchangeMichel Abdalla, Manuel Barbosa, Tatiana Bradley, Stanislaw Jarecki 等CRYPTO 2020 · 被引用 42 次
- Under What Conditions Is Encrypted Key Exchange Actually Secure?Jake Januzelli, Lawrence Roy, Jiayu XuEUROCRYPT 2025 · 被引用 7 次
- Minimal Symmetric PAKE and 1-out-of-N OT from Programmable-Once Public FunctionsIan McQuoid, Mike Rosulek, Lawrence RoyCCS 2020
- Tightly-Secure Authenticated Key Exchange, RevisitedTibor Jager, Eike Kiltz, Doreen Riepel, Sven SchägeEUROCRYPT 2021 · 被引用 39 次
