DocumentCode
46573
Title
Efficient Two-Server Password-Only Authenticated Key Exchange
Author
Xun Yi ; San Ling ; Huaxiong Wang
Author_Institution
Sch. of Eng. & Sci., Victoria Univ., Melbourne, VIC, Australia
Volume
24
Issue
9
fYear
2013
fDate
Sept. 2013
Firstpage
1773
Lastpage
1782
Abstract
Password-authenticated key exchange (PAKE) is where a client and a server, who share a password, authenticate each other and meanwhile establish a cryptographic key by exchange of messages. In this setting, all the passwords necessary to authenticate clients are stored in a single server. If the server is compromised, due to, for example, hacking or even insider attack, passwords stored in the server are all disclosed. In this paper, we consider a scenario where two servers cooperate to authenticate a client and if one server is compromised, the attacker still cannot pretend to be the client with the information from the compromised server. Current solutions for two-server PAKE are either symmetric in the sense that two peer servers equally contribute to the authentication or asymmetric in the sense that one server authenticates the client with the help of another server. This paper presents a symmetric solution for two-server PAKE, where the client can establish different cryptographic keys with the two servers, respectively. Our protocol runs in parallel and is more efficient than existing symmetric two-server PAKE protocol, and even more efficient than existing asymmetric two-server PAKE protocols in terms of parallel computation.
Keywords
authorisation; cryptographic protocols; client authentication; cryptographic key; hacking; insider attack; parallel computation; peer servers; two-server PAKE protocols; two-server password-only authenticated key exchange; Authentication; Dictionaries; Encryption; Protocols; Servers; Diffie-Hellman key exchange; ElGamal encryption; Password-authenticated key exchange; dictionary attack;
fLanguage
English
Journal_Title
Parallel and Distributed Systems, IEEE Transactions on
Publisher
ieee
ISSN
1045-9219
Type
jour
DOI
10.1109/TPDS.2012.282
Filename
6311402
Link To Document