论文标题

前向安全有效的两因素身份验证协议

A Forward-secure Efficient Two-factor Authentication Protocol

论文作者

Murdoch, Steven J., Abadi, Aydin

论文摘要

依赖于知识因素(例如PIN)和设备拥有的两因素身份验证(2FA)方案已广受欢迎。这些方案中的一些仍然安全,即使(a)观察客户端和服务器之间的流量,并且(b)可以进行物理访问客户的设备或其PIN或违反服务器的物理访问。但是,这些解决方案有几个缺点。即,他们(i)要求客户记住多个秘密值以证明其身份,(ii)涉及多个模块化指数,并且(iii)在非标准的随机Oracle模型中。在这项工作中,我们提出了一个2FA协议,该协议在解决上述缺点的同时抵制了如此强大的对手。我们的协议要求客户仅记住单个秘密值/PIN,不涉及任何模块化指数,并且是标准模型。这是第一个提供这些功能而无需使用可信赖芯片组的功能的产品。该协议还比最先进的解决方案施加了高达40%的通信开销。

Two-factor authentication (2FA) schemes that rely on a combination of knowledge factors (e.g., PIN) and device possession have gained popularity. Some of these schemes remain secure even against strong adversaries that (a) observe the traffic between a client and server, and (b) have physical access to the client's device, or its PIN, or breach the server. However, these solutions have several shortcomings; namely, they (i) require a client to remember multiple secret values to prove its identity, (ii) involve several modular exponentiations, and (iii) are in the non-standard random oracle model. In this work, we present a 2FA protocol that resists such a strong adversary while addressing the above shortcomings. Our protocol requires a client to remember only a single secret value/PIN, does not involve any modular exponentiations, and is in a standard model. It is the first one that offers these features without using trusted chipsets. This protocol also imposes up to 40% lower communication overhead than the state-of-the-art solutions do.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源