Concepedia

Publication | Closed Access

The Secure Remote Password Protocol.

439

Citations

7

References

1998

Year

Thomas D. Wu

Unknown Venue

TLDR

The paper introduces a new password authentication and key‑exchange protocol designed for authenticating users and exchanging keys over untrusted networks. The protocol uses zero‑knowledge proofs combined with asymmetric key exchange to provide efficient authentication and key exchange, outperforming methods such as Augmented EKE and B‑SPEKE. The protocol resists dictionary attacks by passive or active intruders, offers perfect forward secrecy, protects stored passwords from direct compromise, and outperforms comparable strong methods such as Augmented EKE and B‑SPEKE.

Abstract

This paper presents a new password authentication and key-exchange protocol suitable for authenticating users and exchanging keys over an untrusted network. The new protocol resists dictionary attacks mounted by either passive or active network intruders, allowing, in principle, even weak passphrases to be used safely. It also o ers perfect forward secrecy, which protects past sessions and passwords against future compromises. Finally, user passwords are stored in a form that is not plaintext-equivalent to the password itself, so an attacker who captures the password database cannot use it directly to compromise security and gain immediate access to the host. This new protocol combines techniques of zero-knowledge proofs with asymmetric key exchange protocols and o ers signi cantly improved performance over comparably strong extended methods that resist stolen-veri er attacks such as Augmented EKE or B-SPEKE.

References

YearCitations

Page 1