Password Hardening Encryption Services Against Malicious Server
Author:
Affiliation:

Clc Number:

TP306

Fund Project:

National Key R&D Program of China (No.2017YFB0802000); National Natural Science Foundation of China (62072054, U2001205, 61772326, 61802241, 61802242); Key Research and Development Program of Shaanxi (No. 2021GY-047); the Fundamental Research Funds for the Central Universities, CHD(300102240102).

  • Article
  • |
  • Figures
  • |
  • Metrics
  • |
  • Reference
  • |
  • Related
  • |
  • Cited by
  • |
  • Materials
  • |
  • Comments
    Abstract:

    Password hardening encryption (PHE) is an emerging primitive in recent years. It can resist offline attack brought by keyword guessing attack from server via adding a third party with crypto services joining the decryption process. This primitive enhances the password authentication protocol and adds encryption functionality. This paper presents an active attack from server in the first scheme that introduced this primitive. This attack combines the idea from a cutting-edge threat called algorithm substitution attack which is undetectable and makes the server capable of launching offline attack. This result shows that the original PHE scheme can not resist attacks from malicious server. Then this study tries to summarize the property that an algorithm substitution attack resistant scheme should have. After that this paper presents a PHE scheme that can resist such kind of attacks from malicious server with simulation results. Finally, this study concludes the result and gives some expectation for future systematic research on interactive protocols under algorithm substitution attack.

    Reference
    Related
    Cited by
Get Citation

赵一,刘行,LIANG Kaitai,明洋,赵祥模,杨波.抵抗恶意服务器的口令增强加密方案.软件学报,2023,34(5):2482-2493

Copy
Share
Article Metrics
  • Abstract:
  • PDF:
  • HTML:
  • Cited by:
History
  • Received:April 15,2021
  • Revised:June 01,2021
  • Adopted:
  • Online: September 30,2022
  • Published:
You are the firstVisitors
Copyright: Institute of Software, Chinese Academy of Sciences Beijing ICP No. 05046678-4
Address:4# South Fourth Street, Zhong Guan Cun, Beijing 100190,Postal Code:100190
Phone:010-62562563 Fax:010-62562533 Email:jos@iscas.ac.cn
Technical Support:Beijing Qinyun Technology Development Co., Ltd.

Beijing Public Network Security No. 11040202500063