CompChall: Addressing Password Guessing Attacks

Computer Science – Cryptography and Security

Scientific paper

Rate now

  [ 0.00 ] – not rated yet Voters 0   Comments 0

Details

6 Pages, 1 Figure; International Conference on Information Technology: Coding and Computing, 2005. ITCC 2005

Scientific paper

10.1109/ITCC.2005.107

Even though passwords are the most convenient means of authentication, they bring along themselves the threat of dictionary attacks. Dictionary attacks may be of two kinds: online and offline. While offline dictionary attacks are possible only if the adversary is able to collect data for a successful protocol execution by eavesdropping on the communication channel and can be successfully countered using public key cryptography, online dictionary attacks can be performed by anyone and there is no satisfactory solution to counter them. This paper presents a new authentication protocol which is called CompChall (computational challenge). The proposed protocol uses only one way hash functions as the building blocks and attempts to eliminate online dictionary attacks by implementing a challenge-response system. This challenge-response system is designed in a fashion that it does not pose any difficulty to a genuine user but is time consuming and computationally intensive for an adversary trying to launch a large number of login requests per unit time as in the case of an online dictionary attack. The protocol is stateless and thus less vulnerable to DoS (Denial of Service) attacks.

No associations

LandOfFree

Say what you really think

Search LandOfFree.com for scientists and scientific papers. Rate them and share your experience with other people.

Rating

CompChall: Addressing Password Guessing Attacks does not yet have a rating. At this time, there are no reviews or comments for this scientific paper.

If you have personal experience with CompChall: Addressing Password Guessing Attacks, we encourage you to share that experience with our LandOfFree.com community. Your opinion is very important and CompChall: Addressing Password Guessing Attacks will most certainly appreciate the feedback.

Rate now

     

Profile ID: LFWR-SCP-O-68185

  Search
All data on this website is collected from public sources. Our data reflects the most accurate information available at the time of publication.