A Password-Based Authenticator: P-Auth

Wei Linna,Qin Zhiguang
DOI: https://doi.org/10.1109/ICCIS.2008.4670916
2008-01-01
Abstract:At present most of the existing authenticators require the input of high entropy keys. However, these keys are hard to remember and a great deal of the existing authentication protocols are based on passwords, the low entropy ones, which are given by users in practice. In this paper, we propose a password-based authenticator P-Auth. P-Auth uses "reputation" to generate high entropy unite secrets that are build on password and session key. It also employs threshold scheme to resist off-line dictionary attack and provide forward security.
What problem does this paper attempt to address?