Authors
Shashank Agrawal, Peihan Miao, Payman Mohassel, Pratyay Mukherjee
Publication date
2018/10/15
Book
Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security
Pages
2042-2059
Description
Token-based authentication is commonly used to enable a single-sign-on experience on the web, in mobile applications and on enterprise networks using a wide range of open standards and network authentication protocols: clients sign on to an identity provider using their username/password to obtain a cryptographic token generated with a master secret key, and store the token for future accesses to various services and applications. The authentication server(s) are single point of failures that if breached, enable attackers to forge arbitrary tokens or mount offline dictionary attacks to recover client credentials. Our work is the first to introduce and formalize the notion of password-based threshold token-based authentication which distributes the role of an identity provider among n servers. Any t servers can collectively verify passwords and generate tokens, while no t-1 servers can forge a valid token or mount offline …
Total citations
20192020202120222023202431710181810
Scholar articles
S Agrawal, P Miao, P Mohassel, P Mukherjee - Proceedings of the 2018 ACM SIGSAC Conference on …, 2018