On the security of PAS (predicate-based authentication service)


Autoria(s): Li, Shujun; Asghar, Hassan Jameel; Pieprzyk, Josef; Sadeghi, Ahmad-Reza; Schmitz, Roland; Wang, Huaxiong
Data(s)

2009

Resumo

Recently a new human authentication scheme called PAS (predicate-based authentication service) was proposed, which does not require the assistance of any supplementary device. The main security claim of PAS is to resist passive adversaries who can observe the whole authentication session between the human user and the remote server. In this paper we show that PAS is insecure against both brute force attack and a probabilistic attack. In particular, we show that its security against brute force attack was strongly overestimated. Furthermore, we introduce a probabilistic attack, which can break part of the password even with a very small number of observed authentication sessions. Although the proposed attack cannot completely break the password, it can downgrade the PAS system to a much weaker system similar to common OTP (one-time password) systems.

Identificador

http://eprints.qut.edu.au/70170/

Publicador

IEEE

Relação

http://ieeexplore.ieee.org/xpl/articleDetails.jsp?arnumber=5380509

DOI:10.1109/ACSAC.2009.27

Li, Shujun, Asghar, Hassan Jameel, Pieprzyk, Josef, Sadeghi, Ahmad-Reza, Schmitz, Roland, & Wang, Huaxiong (2009) On the security of PAS (predicate-based authentication service). In Proceedings of 2009 Annual Computer Security Applications Conference (ACSAC '09), IEEE, Honolulu, Hawaii, pp. 209-218.

http://purl.org/au-research/grants/ARC/DP0987734

NATIONAL RESEARCH FO/NRF-CRP2-2007-03

SINGAPORE MINISTRY O/T206B2204

UNIVERSITY OF KONSTA/Fellowship

MQRES/International PhD Scholarship

CACE/EU funding

Direitos

Copyright 2009 IEEE

Fonte

School of Electrical Engineering & Computer Science; Science & Engineering Faculty

Palavras-Chave #PAS #Authentication #Matsumoto-Imai threat model #Attack #Security #Usability #OTP (one-time password)
Tipo

Conference Paper