Skip to main content
Back to USENIX
  • Conferences
  • Students
Sign in

USENIX Conference Policies

  • Event Code of Conduct
  • Conference Network Policy
  • Statement on Environmental Responsibility Policy

PDM: A New Strong Password-Based Protocol

In this paper we present PDM (Password Derived Mod-uli), a new approach to strong password-based protocols usable either for mutual authentication or for download-ing security information such as the userÕs private key. We describe how the properties desirable for strong password mutual authentication differ from the proper-ties desirable for credentials download. In particular, a protocol used solely for credentials download can be simpler and less expensive than one used for mutual authentication since some properties (such as authenti-cation of the server) are not necessary for credentials download. The features necessary for mutual authenti-cation can be easily added to a credentials download protocol, but many of the protocols designed for mutual authentication are not as desirable for use in credentials download as protocols like PDM and basic EKE and SPEKE because they are unnecessarily expensive when used for that purpose. PDMÕs performance is vastly more expensive at the client than any of the protocols in the literature, but it is more efficient at the server. We claim that performance at the server, since a server must handle a large and potentially unpredictable number of clients, is more important than performance at the client, assuming that client performance is Ògood enoughÓ. We describe PDM for credentials download, and then show how to enhance it to have the properties desirable for mutual authentication. In particular, the enhancement we advocate for allowing PDM to avoid storing a pass-word- equivalent at the server is less expensive than existing schemes, and our approach can be used as a more efficient (at the server) variant of augmented EKE and SPEKE than the currently published schemes. PDM is important because it is a very different approach to the problem than any in the literature, we believe it to be unencumbered by patents, and because it can be a lot less expensive at the server than existing schemes.

Charlie Kaufman, Iris Associates

Radia Perlman, Sun Microsystems Laboratories

BibTeX
@inproceedings {270897,
author = {Charlie Kaufman and Radia Perlman},
title = {{PDM}: A New Strong {Password-Based} Protocol},
booktitle = {10th USENIX Security Symposium (USENIX Security 01)},
year = {2001},
address = {Washington, D.C.},
url = {https://www.usenix.org/conference/10th-usenix-security-symposium/pdm-new-strong-password-based-protocol},
publisher = {USENIX Association},
month = aug
}
Download

Links

Paper: 
http://www.usenix.org/events/sec01/full_papers/kaufman/kaufman.pdf
Slides: 
http://www.usenix.org/events/sec01/kaufman.pdf
  • Log in or register to post comments

© USENIX
EIN 13-3055038

  • Privacy Policy
  • Contact Us