Indistinguishability and unextractablility of password-based authentication in blockchain
Indistinguishability and unextractablility of password-based authentication in blockchain
复制标题
DOI:
10.1016/j.future.2020.05.009
复制
发表时间:
2020-11
期刊:
影响因子:
--
通讯作者:
Xinyi Huang;Yuexin Zhang
中科院分区:
文献类型:
--
作者:
Xinyi Huang;Yuexin Zhang
Password is commonly used to protect Bitcoin wallet, the most known application of blockchain. In this paper, we investigate a subtle issue when forgetting password: The account owner uses guessed passwords during the authentication with a service provider. This is different from password guessing by cyber attackers, because passwords guessed by the account owner are (most likely) his/her passwords (or their minor variations) registered with other service providers. Thus, the confidentiality of incorrect passwords in unsuccessful authentication needs protection. To capture this security requirement, we define two security goals: Indistinguishability of Incorrect Passwords (IND-PW) and Unextractablility of Incorrect Passwords (UNE-PW). Our analysis shows that: (1) IND-PW is NOT achievable if password is the only authentication credential of the client, and (2) Two common authentication methods in online services, Basic and Digest Access Authentication (in conjunction with SSL), CANNOT provide UNE-PW.