Paper published in a book (Scientific congresses, symposiums and conference proceedings)
HoneyPAKEs
Lopez Becerra, José Miguel; Roenne, Peter; Ryan, Peter et al.
2018In Security Protocols XXVI: Lecture Notes in Computer Science
Peer reviewed
 

Files


Full Text
2.1-ryan.pdf
Publisher postprint (321.57 kB)
Download

All documents in ORBilu are protected by a user license.

Send to



Details



Keywords :
PAKEs; Honeywords; passwords; login; authentication
Abstract :
[en] We combine two security mechanisms: using a Password-based Authenticated Key Establishment (PAKE) protocol to protect the password for access control and the Honeywords construction of Juels and Rivest to detect loss of password files. The resulting construction combines the properties of both mechanisms: ensuring that the password is intrinsically protected by the PAKE protocol during transmission and the Honeywords mechanisms for detecting attempts to exploit a compromised password file. Our constructions lead very naturally to two factor type protocols. An enhanced version of our protocol further provides protection against a compromised login server by ensuring that it does not learn the index to the true password.
Research center :
Interdisciplinary Centre for Security, Reliability and Trust (SnT) > Applied Security and Information Assurance Group (APSIA)
Disciplines :
Computer science
Author, co-author :
Lopez Becerra, José Miguel ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT)
Roenne, Peter ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT)
Ryan, Peter ;  University of Luxembourg > Faculty of Science, Technology and Communication (FSTC) > Computer Science and Communications Research Unit (CSC)
Sala, Petra ;  University of Luxembourg > Faculty of Science, Technology and Communication (FSTC) > Computer Science and Communications Research Unit (CSC)
External co-authors :
no
Language :
English
Title :
HoneyPAKEs
Publication date :
27 November 2018
Event name :
Security Protocols XXVI: 26th International Workshop
Event place :
Cambridge, United Kingdom
Event date :
from 19-03-2018 to 21-03-2018
By request :
Yes
Audience :
International
Main work title :
Security Protocols XXVI: Lecture Notes in Computer Science
Publisher :
Springer International Publishing
ISBN/EAN :
978-3-030-03251-7
Pages :
63-77
Peer reviewed :
Peer reviewed
Focus Area :
Security, Reliability and Trust
FnR Project :
FNR8293135 - A Theory Of Matching Sessions, 2014 (01/05/2015-30/04/2018) - Peter Y. A. Ryan
Funders :
FNR - Fonds National de la Recherche [LU]
Available on ORBilu :
since 07 January 2019

Statistics


Number of views
203 (16 by Unilu)
Number of downloads
216 (58 by Unilu)

Bibliography


Similar publications



Contact ORBilu