Undetectable on-line password guessing attacks

  • Authors:
  • Yun Ding;Patrick Horster

  • Affiliations:
  • University of Technology Chemnitz-Zwickau, Chemnitz, Germany;University of Technology Chemnitz-Zwickau, Chemnitz, Germany

  • Venue:
  • ACM SIGOPS Operating Systems Review
  • Year:
  • 1995

Quantified Score

Hi-index 0.00

Visualization

Abstract

Several 3-party-based authentication protocols have been proposed, which are resistant to off-line password guessing attacks. We show that they are not resistant to a new type of attack called "undetectable on-line password guessing attack". The authentication server is not able to notice this kind of attack from the clients' (attacker's) requests, because they don't include enough information about the clients (or attacker). Either freshness or authenticity of these requests is not guaranteed. Thus the authentication server responses and leaks verifiable information for an attacker to verify his guess.