Permutation-Based Hash Chains with Application to Password Hashing
Abstract: Hash chain based password systems are a useful way to guarantee authentication with one-time passwords. The core idea dates back to Lamport, and is specified in RFC 1760 as S/Key. At CCS 2017, Kogan et al. introduced T/Key, an improved password system where one-time passwords are only valid for a limited time period. They proved security of their construction in the random oracle model under a basic modeling of the adversary. In this work, we make various advances in the analysis and instantiation of hash chain based password systems. Firstly, we describe a slight abstraction called U/Key that allows for more flexibility in the instantiation and analysis, and we develop a security model that refines the adversarial strength into offline and online complexity, that can be used beyond the random oracle model, and that allows to argue multi-user security directly. Secondly, we derive a new security proof of U/Key in the random oracle model, as well as dedicated and tighter security pr.... https://ojs.ub.rub.de/index.php/ToSC/article/view/11955
- Standort
-
Deutsche Nationalbibliothek Frankfurt am Main
- Umfang
-
Online-Ressource
- Sprache
-
Englisch
- Erschienen in
-
Permutation-Based Hash Chains with Application to Password Hashing ; volume:2024 ; number:4 ; year:2024
IACR transactions on symmetric cryptology ; 2024, Heft 4 (2024)
- Urheber
-
Lefevre, Charlotte
Mennink, Bart
- DOI
-
10.46586/tosc.v2024.i4.249-286
- URN
-
urn:nbn:de:101:1-2412181758586.739249015063
- Rechteinformation
-
Open Access; Der Zugriff auf das Objekt ist unbeschränkt möglich.
- Letzte Aktualisierung
-
15.08.2025, 07:29 MESZ
Datenpartner
Deutsche Nationalbibliothek. Bei Fragen zum Objekt wenden Sie sich bitte an den Datenpartner.
Beteiligte
- Lefevre, Charlotte
- Mennink, Bart