Anonymous Two-Factor Authentication in Distributed Systems: Certain Goals Are Beyond Attainment

Anonymous Two-Factor Authentication in Distributed Systems: Certain Goals Are Beyond Attainment
复制标题

分布式系统中的匿名双因素身份验证:某些目标无法实现

DOI:
10.1109/tdsc.2014.2355850
复制
发表时间:
2015-07
影响因子:
7.3
通讯作者:
Chu Chao-Hsien
Chu Chao-Hsien
中科院分区:
计算机科学2区
文献类型:
--
作者:
Wang Ding;He Debiao;Wang Ping;Chu Chao-Hsien

文献摘要

参考文献

被引文献

相似文献

尽管经过了二十年的深入研究,设计一个实用的匿名双因素认证方案仍然是一个挑战,因为设计者面临着一系列令人印象深刻的安全要求(例如,对智能卡丢失攻击的抵抗力)和期望的属性(例如,本地密码更新)。已经提出了许多解决方案,但它们中的大多数很快就被发现无法满足一些关键的安全要求或缺乏一些重要的功能。为了克服这种不令人满意的情况,研究人员经常围绕它工作,希望有一个新的建议(但到目前为止还没有人成功),而很少关注的基本问题:是否有固有的限制,阻止我们设计一个“理想”的计划,满足所有可取的目标?在这项工作中,我们的目标是提供一个明确的答案,这个问题。我们首先回顾两个最重要的建议,即蔡等人。的方案和李的方案,揭示了设计此类方案的一些微妙之处和挑战。然后,我们系统地探讨了设计准则之间的内在冲突和不可避免的权衡。我们的研究结果表明,在目前广泛接受的对抗模型下,某些目标是无法实现的。这也表明了对Huang等人在2014年留下的开放问题的否定回答。据我们所知,本研究的第一步,了解匿名双因素认证的基本评价指标,我们相信这将有助于更好地设计匿名双因素协议,提供可接受的可用性,安全性和隐私之间的权衡。
Despite two decades of intensive research, it remains a challenge to design a practical anonymous two-factor authentication scheme, for the designers are confronted with an impressive list of security requirements (e.g., resistance to smart card loss attack) and desirable attributes (e.g., local password update). Numerous solutions have been proposed, yet most of them are shortly found either unable to satisfy some critical security requirements or short of a few important features. To overcome this unsatisfactory situation, researchers often work around it in hopes of a new proposal (but no one has succeeded so far), while paying little attention to the fundamental question: whether or not there are inherent limitations that prevent us from designing an “ideal” scheme that satisfies all the desirable goals? In this work, we aim to provide a definite answer to this question. We first revisit two foremost proposals, i.e. Tsai et al.'s scheme and Li's scheme, revealing some subtleties and challenges in designing such schemes. Then, we systematically explore the inherent conflicts and unavoidable trade-offs among the design criteria. Our results indicate that, under the current widely accepted adversarial model, certain goals are beyond attainment. This also suggests a negative answer to the open problem left by Huang et al. in 2014. To the best of knowledge, the present study makes the first step towards understanding the underlying evaluation metric for anonymous two-factor authentication, which we believe will facilitate better design of anonymous two-factor protocols that offer acceptable trade-offs among usability, security and privacy.
DOI: 10.1016/j.jss.2012.06.063
发表时间: 2012-12-01
影响因子: 3.5
作者:
Kim, Tae Hyun;Kim, ChangKyun;Park, IlHwan
通讯作者: Park, IlHwan
DOI: --
发表时间: 1979
期刊: --
影响因子: --
作者:
J. Purcell;Brocard Sewell;J. Sullivan;P. Hunt;G. Macdonald
通讯作者: J. Purcell;Brocard Sewell;J. Sullivan;P. Hunt;G. Macdonald
DOI: 10.1007/3-540-45539-6_11
发表时间: 2000-05
期刊: IACR Cryptol. ePrint Arch.
影响因子: --
作者:
M. Bellare;D. Pointcheval;P. Rogaway
通讯作者: M. Bellare;D. Pointcheval;P. Rogaway
DOI: 10.1109/tpds.2010.206
发表时间: 2011-08-01
影响因子: 5.3
作者:
Huang, Xinyi;Xiang, Yang;Deng, Robert H.
通讯作者: Deng, Robert H.
DOI: 10.1109/tc.2002.1004593
发表时间: 2002-05-01
影响因子: 3.7
作者:
Messerges, TS;Dabbish, EA;Sloan, RH
通讯作者: Sloan, RH