Sciweavers

ACISP
2010
Springer

One-Time-Password-Authenticated Key Exchange

13 years 6 months ago
One-Time-Password-Authenticated Key Exchange
To reduce the damage of phishing and spyware attacks, banks, governments, and other security-sensitive industries are deploying one-time password systems, where users have many passwords and use each password only once. If a single password is compromised, it can be only be used to impersonate the user once, limiting the damage caused. However, existing practical approaches to one-time passwords have been susceptible to sophisticated phishing attacks. We give a formal security treatment of this important practical problem. We consider the use of onetime passwords in the context of password-authenticated key exchange (PAKE), which allows for mutual authentication, session key agreement, and resistance to phishing attacks. We describe a security model for the use of one-time passwords, explicitly considering the compromise of past (and future) one-time passwords, and show a general technique for building a secure one-time-PAKE protocol from any secure PAKE protocol. Our techniques also ...
Kenneth G. Paterson, Douglas Stebila
Added 26 Oct 2010
Updated 26 Oct 2010
Type Conference
Year 2010
Where ACISP
Authors Kenneth G. Paterson, Douglas Stebila
Comments (0)