抵抗恶意服务器的口令增强加密方案

Translated title of the contribution: Password Hardening Encryption Services Against Malicious Server

Yi Zhao*, Hang Liu, Kaitai Liang, Yang Ming, Xiang Mo Zhao, Bo Yang

*Corresponding author for this work

Research output: Contribution to journalArticleScientificpeer-review

Abstract

Password hardening encryption (PHE) is an emerging primitive in recent years. It can resist offline attack brought by keyword guessing attack from server via adding a third party with crypto services joining the decryption process. This primitive enhances the password authentication protocol and adds encryption functionality. This paper presents an active attack from server in the first scheme that introduced this primitive. This attack combines the idea from a cutting-edge threat called algorithm substitution attack which is undetectable and makes the server capable of launching offline attack. This result shows that the original PHE scheme can not resist attacks from malicious server. Then this study tries to summarize the property that an algorithm substitution attack resistant scheme should have. After that this paper presents a PHE scheme that can resist such kind of attacks from malicious server with simulation results. Finally, this study concludes the result and gives some expectation for future systematic research on interactive protocols under algorithm substitution attack.

Translated title of the contributionPassword Hardening Encryption Services Against Malicious Server
Original languageChinese
Pages (from-to)2482-2493
Number of pages12
JournalRuan Jian Xue Bao/Journal of Software
Volume34
Issue number5
DOIs
Publication statusPublished - 2023

Keywords

  • algorithm substitution attack
  • malicious server
  • password hardening encryption (PHE)
  • undetectable

Fingerprint

Dive into the research topics of 'Password Hardening Encryption Services Against Malicious Server'. Together they form a unique fingerprint.

Cite this