Encrypted Key Exchange: Password-Based Protocols SecureAgainst Dictionary Attacks

  • Authors:
  • Steven M. Bellovin;Michael Merritt

  • Affiliations:
  • -;-

  • Venue:
  • SP '92 Proceedings of the 1992 IEEE Symposium on Security and Privacy
  • Year:
  • 1992

Quantified Score

Hi-index 0.00

Visualization

Abstract

Classical cryptographic protocols based on use-rchosenkeys allow an attacker to mount password-guessingattacks. We introduce a novel combination of asymmetric (public-key) and symmetric (secret-key) cvptography that allow two parties sharing a common password to exchange confidential and authenticated information over an insecure network. These protocols are secure against active attacks, and have the property that the password is protected against off-line "dictionary" attacks. There are a number of otheruseful applications as well, including secure public telephones.