Secure Password Authentication for Distributed Computing

  • Authors:
  • Seung Wook Jung;Souhwan Jung

  • Affiliations:
  • Soongsil University Communication Network Security Lab, Soongsil univ 1-1 Sangdo-dong Dongjak-Gu Seoul 256-743, Korea;Soongsil University Communication Network Security Lab, Soongsil univ 1-1 Sangdo-dong Dongjak-Gu Seoul 256-743, Korea

  • Venue:
  • Computational Intelligence and Security
  • Year:
  • 2007

Quantified Score

Hi-index 0.00

Visualization

Abstract

This paper describes secure password-based authentication involving a trusted third party, while the previous secure password authentication schemes focused on authentication involving two parties who shares the password. Kerberos is a well-known password-based authentication protocol involving a trusted third party. However, Kerberos is weak against the dictionary attack, suffers from a single point of failure. Additionally, Kerberos cannot provide a forward secrecy, which protects past sessions and further compromise, when a password is revealed. Our password authentication schemes provides Single Sign On like Kerberos and is secure against on/off-line dictionary attack. Moreover, The schemes provide a forward secrecy, and reduces the damage of the single point of failure.