loading...
 This Article 
   
 Share 
   
 Bibliographic References 
   
 Add to: 
 
Digg
Furl
Spurl
Blink
Simpy
Google
Del.icio.us
Y!MyWeb
 
 Search 
   
19th Annual Computer Security Applications Conference (ACSAC '03)
An Intrusion-Tolerant Password Authentication System
Las Vegas, Nevada
December 08-December 12
ISBN: 0-7692-2041-3
Xunhua Wang, James Madison University, Harrisonburg, VA
M. Hossain Heydari, James Madison University, Harrisonburg, VA
Hua Lin, Wachovia Corporation, Rockville, MD
In a password-based authentication system, to authenticate a user, a server typically stores password verification data (PVD), which is a value derived from the user's password using publicly known functions. For those users whose passwords fall within an attacker's dictionary, their PVDs, if stolen (for example, through server compromise), will allow the attacker to mount off-line dictionary attacks. In this article, we describe a password authentication system that can tolerate server compromises. The described system uses multiople (say n) servers to share password verification data and never reconstructs the shared PVD during user authentications. Only a threshold number (say t, t ≤ n) of these servers are required for a user authentication and compromising up to (t - 1) of these servers will not allow an attacker to mount off-line dictionary attacks, even if a user's password falls within the attacker's dictionary. The described system can still function if some of the servers are unavailable. In this paper, we give the system architecture and implementation details. Our experimental results show that the described system works well. The given system can be used to build intrusion-tolerant applications.
Index Terms:
Intrusion tolerance, off-line dictionary attack, password-authenticated key exchange (PAKE)
Citation:
Xunhua Wang, M. Hossain Heydari, Hua Lin, "An Intrusion-Tolerant Password Authentication System," acsac, pp.110, 19th Annual Computer Security Applications Conference (ACSAC '03), 2003
Usage of this product signifies your acceptance of the Terms of Use.