Client-Server Password Recovery

被引:0
|
作者
Chmielewski, Lukasz [1 ]
Hoepman, Jaap-Henk [1 ]
van Rossum, Peter [1 ]
机构
[1] Radboud Univ Nijmegen, Digital Secur Grp, Nijmegen, Netherlands
来源
ON THE MOVE TO MEANINGFUL INTERNET SYSTEMS: OTM 2009, PT 2 | 2009年 / 5871卷
关键词
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Human memory is not perfect people constantly memorize new facts and forget old ones. One example is forgetting a password, a common problem raised at IT help desks. We present several protocols that allow a user to automatically recover a password from a server using partial knowledge of the password. These protocols can be easily adapted to the personal entropy setting [7], where a user can recover a password only if he can answer a large enough subset of personal questions. We introduce client-server password recovery methods, in which the recovery data are stored at the server, and the recovery procedures are integrated into the login procedures. These methods apply to two of the most common types of password based authentication systems. The security of these solutions is significantly better than the security of presently proposed password recovery schemes. For our protocols we propose a variation of threshold encryption [5, 8, 16] that might be of independent interest.
引用
收藏
页码:861 / 878
页数:18
相关论文
共 50 条
  • [1] A new one time password mechanism for client-server applications
    Shukla, Varun
    Chaturvedi, Atul
    Srivastava, Neelam
    JOURNAL OF DISCRETE MATHEMATICAL SCIENCES & CRYPTOGRAPHY, 2019, 22 (08): : 1393 - 1406
  • [2] Synchronization and recovery in a client-server storage system
    Panagos E.
    Biliris A.
    The VLDB Journal, 1997, 6 (3) : 209 - 223
  • [3] BEWARE OF CLIENT-SERVER
    HADBURG, BP
    DATAMATION, 1995, 41 (22): : 90 - 90
  • [4] IS - THE CLIENT-SERVER CONNECTION
    BOGENSCHUTZ, C
    CRATER, TL
    HEDRICK, DR
    HILL, CRD
    JOHNSON, M
    PIZZELANTI, T
    WERTZ, F
    PIMA MAGAZINE, 1994, 76 (04): : 22 - 25
  • [5] BACKING INTO CLIENT-SERVER
    BAUM, D
    DATAMATION, 1994, 40 (20): : 71 - 77
  • [6] DEFINE CLIENT-SERVER
    FORSELL, C
    DATAMATION, 1995, 41 (19): : 12 - 12
  • [8] CLIENT-SERVER FEASIBILITY
    DUE, RT
    INFORMATION SYSTEMS MANAGEMENT, 1994, 11 (03) : 79 - 82
  • [9] CLIENT-SERVER TRENDS
    LAROCQUE, J
    IEEE SPECTRUM, 1994, 31 (04) : 48 - 50
  • [10] CLIENT-SERVER COMPUTING
    SINHA, A
    COMMUNICATIONS OF THE ACM, 1992, 35 (07) : 77 - 98