Two-factor Password-authenticated Key Exchange with End-to-end Security

Two-factor Password-authenticated Key Exchange with End-to-end Security
复制标题

DOI:
10.1145/3446807
复制
发表时间:
2021-04
期刊:
ACM Transactions on Privacy and Security (TOPS)
影响因子:
--
通讯作者:
Stanislaw Jarecki;Mohammed Jubur;H. Krawczyk;Nitesh Saxena;Maliheh Shirvanian
Stanislaw Jarecki;Mohammed Jubur;H. Krawczyk;Nitesh Saxena;Maliheh Shirvanian
中科院分区:
其他
文献类型:
--
作者:
Stanislaw Jarecki;Mohammed Jubur;H. Krawczyk;Nitesh Saxena;Maliheh Shirvanian

文献摘要

相似文献

我们提出了一个安全的双因素认证(TFA)计划的基础上,用户拥有一个密码和一个加密的设备。安全性是“端到端”的,在这个意义上,攻击者可以攻击系统的所有部分,包括所有通信链路和任何一方的子集(服务器,设备,客户端终端),可以学习用户的密码,并在线和离线执行主动和被动攻击。在所有情况下,该计划提供了最高的可达到的安全界限给定的一组受损的组件。我们的解决方案使用Jarecki等人定义的任何设备增强密码认证密钥交换(PAKE)构建TFA方案,以及由Vaudenay定义的任何短认证字符串(SAS)消息认证。我们展示了这种模块化结构的一个有效实例,它利用任何基于密码的客户端-服务器身份验证方法,依赖或不依赖公钥基础设施。该方案的安全性证明在一个正式的模型,我们制定为传统的PAKE模型的扩展。我们还报告了我们的计划,包括TLS为基础的和无PKI的变种,以及SAS机制的几个实例,所有这些都证明了我们的方法的实用性的原型实现。最后,我们提出了一个可用性研究,评估我们的协议与传统的基于PIN的TFA方法在效率、潜在错误、用户体验和底层手动过程的安全感知方面的可行性。
We present a secure two-factor authentication (TFA) scheme based on the user’s possession of a password and a crypto-capable device. Security is “end-to-end” in the sense that the attacker can attack all parts of the system, including all communication links and any subset of parties (servers, devices, client terminals), can learn users’ passwords, and perform active and passive attacks, online and offline. In all cases the scheme provides the highest attainable security bounds given the set of compromised components. Our solution builds a TFA scheme using any Device-enhanced Password-authenticated Key Exchange (PAKE), defined by Jarecki et al., and any Short Authenticated String (SAS) Message Authentication, defined by Vaudenay. We show an efficient instantiation of this modular construction, which utilizes any password-based client-server authentication method, with or without reliance on public-key infrastructure. The security of the proposed scheme is proven in a formal model that we formulate as an extension of the traditional PAKE model. We also report on a prototype implementation of our schemes, including TLS-based and PKI-free variants, as well as several instantiations of the SAS mechanism, all demonstrating the practicality of our approach. Finally, we present a usability study evaluating the viability of our protocol contrasted with the traditional PIN-based TFA approach in terms of efficiency, potential for errors, user experience, and security perception of the underlying manual process.1