One-Time verifier-based encrypted key exchange

  • Authors:
  • Michel Abdalla;Olivier Chevassut;David Pointcheval

  • Affiliations:
  • Dépt d'informatique, École normale supérieure, Paris Cedex 05, France;Lawrence Berkeley National Laboratory, Berkeley, CA;Dépt d'informatique, École normale supérieure, Paris Cedex 05, France

  • Venue:
  • PKC'05 Proceedings of the 8th international conference on Theory and Practice in Public Key Cryptography
  • Year:
  • 2005

Quantified Score

Hi-index 0.00

Visualization

Abstract

“Grid” technology enables complex interactions among computational and data resources; however, to be deployed in production computing environments “Grid” needs to implement additional security mechanisms. Recent compromises of user and server machines at Grid sites have resulted in a need for secure password-authentication key-exchange technologies. AuthA is an example of such a technology considered for standardization by the IEEE P1363.2 working group. Unfortunately in its current form AuthA does not achieve the notion of forward-secrecy in a provably-secure way nor does it allow a Grid user to log into his account using an un-trusted computer. This paper addresses this void by first proving that AuthA indeed achieves this goal, and then by modifying it in such a way that it is secure against attacks using captured user passwords or server data.