Permutation-Based Hash Chains with Application to Password Hashing

Abstract: Hash chain based password systems are a useful way to guarantee authentication with one-time passwords. The core idea dates back to Lamport, and is specified in RFC 1760 as S/Key. At CCS 2017, Kogan et al. introduced T/Key, an improved password system where one-time passwords are only valid for a limited time period. They proved security of their construction in the random oracle model under a basic modeling of the adversary. In this work, we make various advances in the analysis and instantiation of hash chain based password systems. Firstly, we describe a slight abstraction called U/Key that allows for more flexibility in the instantiation and analysis, and we develop a security model that refines the adversarial strength into offline and online complexity, that can be used beyond the random oracle model, and that allows to argue multi-user security directly. Secondly, we derive a new security proof of U/Key in the random oracle model, as well as dedicated and tighter security pr.... https://ojs.ub.rub.de/index.php/ToSC/article/view/11955

Standort
Deutsche Nationalbibliothek Frankfurt am Main
Umfang
Online-Ressource
Sprache
Englisch

Erschienen in
Permutation-Based Hash Chains with Application to Password Hashing ; volume:2024 ; number:4 ; year:2024
IACR transactions on symmetric cryptology ; 2024, Heft 4 (2024)

Urheber
Lefevre, Charlotte
Mennink, Bart

DOI
10.46586/tosc.v2024.i4.249-286
URN
urn:nbn:de:101:1-2412181758586.739249015063
Rechteinformation
Open Access; Der Zugriff auf das Objekt ist unbeschränkt möglich.
Letzte Aktualisierung
15.08.2025, 07:29 MESZ

Datenpartner

Dieses Objekt wird bereitgestellt von:
Deutsche Nationalbibliothek. Bei Fragen zum Objekt wenden Sie sich bitte an den Datenpartner.

Beteiligte

  • Lefevre, Charlotte
  • Mennink, Bart

Ähnliche Objekte (12)