Delayed password disclosure (Q2379116)

From MaRDI portal
scientific article
Language Label Description Also known as
English
Delayed password disclosure
scientific article

    Statements

    Delayed password disclosure (English)
    0 references
    0 references
    0 references
    15 January 2009
    0 references
    Summary: We present a new authentication protocol called Delayed Password Disclosure (DPD). Based on the traditional username and password paradigm, the protocol's goal is aimed at reducing the effectiveness of phishing/spoofing attacks that are becoming increasingly problematic for Internet users. This is done by providing the user with dynamic feedback while password entry occurs. While this is a process that would normally be frowned upon by the cryptographic community, we argue that it may result in more effective security than that offered by currently proposed `cryptographically acceptable' alternatives. While the protocol cannot prevent partial disclosure of one's password to the phisher, it does provide a user with the tools necessary to recognise an ongoing phishing attack, and prevent the disclosure of his/her entire password, providing graceful security degradation.
    0 references
    0 references
    decisional and static Diffie-Hellman
    0 references
    doppelganger
    0 references
    oblivious transfer
    0 references
    OT
    0 references
    password authenticated key exchange
    0 references
    PAKE
    0 references
    phishing
    0 references
    secure user interfaces
    0 references
    0 references