Indistinguishability and unextractablility of password-based authentication in blockchain

Indistinguishability and unextractablility of password-based authentication in blockchain
复制标题

DOI:
10.1016/j.future.2020.05.009
复制
发表时间:
2020-11
期刊:
Future Gener. Comput. Syst.
影响因子:
--
通讯作者:
Xinyi Huang;Yuexin Zhang
Xinyi Huang;Yuexin Zhang
中科院分区:
其他
文献类型:
--
作者:
Xinyi Huang;Yuexin Zhang

文献摘要

相似文献

密码通常用于保护比特币钱包,这是区块链最知名的应用。在本文中,我们研究了一个微妙的问题时忘记密码:帐户所有者使用猜测的密码在认证与服务提供商。这与网络攻击者猜测密码不同,因为账户所有者猜测的密码(很可能)是他/她在其他服务提供商处注册的密码(或其微小变化)。因此,需要保护不成功认证中的不正确密码的机密性。为了满足这一安全需求,我们定义了两个安全目标:不正确密码不可识别性(IND-PW)和不正确密码不可提取性(UNE-PW)。我们的分析表明:(1)如果密码是客户端的唯一认证凭证,则无法实现IND-PW,以及(2)在线服务中的两种常见认证方法,基本和摘要访问认证(结合SSL),不能提供UNE-PW。
Password is commonly used to protect Bitcoin wallet, the most known application of blockchain. In this paper, we investigate a subtle issue when forgetting password: The account owner uses guessed passwords during the authentication with a service provider. This is different from password guessing by cyber attackers, because passwords guessed by the account owner are (most likely) his/her passwords (or their minor variations) registered with other service providers. Thus, the confidentiality of incorrect passwords in unsuccessful authentication needs protection. To capture this security requirement, we define two security goals: Indistinguishability of Incorrect Passwords (IND-PW) and Unextractablility of Incorrect Passwords (UNE-PW). Our analysis shows that: (1) IND-PW is NOT achievable if password is the only authentication credential of the client, and (2) Two common authentication methods in online services, Basic and Digest Access Authentication (in conjunction with SSL), CANNOT provide UNE-PW.