Journal of Networks, Vol 4, No 3 (2009), 200-207, May 2009
doi:10.4304/jnw.4.3.200-207

User Authentication with Provable Security against Online Dictionary Attacks

Yongzhong He, Zhen Han

Abstract


Dictionary attacks are the best known threats on the password-based authentication schemes. Based on Reverse Turing Test (RTT), some usable and scalable authentication schemes are proposed to defeat online dictionary attacks mounted by automated programs. However it is found that these authentication schemes are vulnerable to various online dictionary attacks. In this paper, a practical decision function is presented, based on which RTT authentication schemes are constructed and shown to be secure against all the known online dictionary attacks. After formally modeling of the adversary, the static and dynamic security of the authentication schemes are proved formally.



Keywords


Online Dictionary attack; Reverse Turing Test; Authentication

References



Full Text: PDF


Journal of Networks (JNW, ISSN 1796-2056)

Copyright @ 2006-2012 by ACADEMY PUBLISHER – All rights reserved.