Paper 2010/393

A Privacy-Flexible Password Authentication Scheme for Multi-Server Environment

Jue-Sam Chou, Yalin Chen, and Chun-Hui Huang

Abstract

Since Kerberos suffers from KDC (Key Distribution Center) compromise and impersonation attack, a multi-server password authentication protocol which highlights no verification table in the server end could therefore be an alternative. Typically, there are three roles in a multi-server password authentication protocol: clients, servers, and a register center which plays the role like KDC in Kerberos. In this paper, we exploit the theoretical basis for implementing a multi-server password authentication system under two constraints: no verification table and user privacy protection. We found that if a system succeeds in privacy protection, it should be implemented either by using a public key cryptosystem or by a register center having a table to record the information shared with corresponding users. Based on this finding, we propose a privacy-flexible system to let a user can employ a random-looking dynamic identity or employ a pseudonym with the register center online or offline to login a server respectively according to his privacy requirement. Compared with other related work, our scheme is not only efficient but also the most conformable to the requirements that previous work suggest.

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
Published elsewhere. Unknown where it was published
Keywords
password authenticationimpersonation attackuser privacy protectionKerberospassword guessing attacksmart card lost attack
Contact author(s)
jschou @ mail nhu edu tw
History
2010-07-13: received
Short URL
https://ia.cr/2010/393
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2010/393,
      author = {Jue-Sam Chou and Yalin Chen and Chun-Hui Huang},
      title = {A Privacy-Flexible Password Authentication Scheme for Multi-Server Environment},
      howpublished = {Cryptology {ePrint} Archive, Paper 2010/393},
      year = {2010},
      url = {https://eprint.iacr.org/2010/393}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.