Matches in SemOpenAlex for { <https://semopenalex.org/work/W2735788045> ?p ?o ?g. }
Showing items 1 to 75 of
75
with 100 items per page.
- W2735788045 abstract "Password managers (aka stores or vaults) allow a user to store and retrieve (usually high-entropy) passwords for her multiple password-protected services by interacting with a device serving the role of the manager (e.g., a smartphone or an online third-party service) on the basis of a single memorable (low-entropy) master password. Existing password managers work well to defeat offline dictionary attacks upon web service compromise, assuming the use of high-entropy passwords is enforced. However, they are vulnerable to leakage of all passwords in the event the device is compromised, due to the need to store the passwords encrypted under the master password and/or the need to input the master password to the device (as in smartphone managers). Evidence exists that password managers can be attractive attack targets. In this paper, we introduce a novel approach to password management, called SPHINX, which remains secure even when the password manager itself has been compromised. In SPHINX, the information stored on the device is information theoretically independent of the user's master password - an attacker breaking into the device learns no information about the master password or the user's site-specific passwords. Moreover, an attacker with full control of the device, even at the time the user interacts with it, learns nothing about the master password - the password is not entered into the device in plaintext form or in any other way that may leak information on it. Unlike existing managers, SPHINX produces strictly high-entropy passwords and makes it compulsory for the users to register these randomized passwords with the web services, hence fully defeating offline dictionary attack upon service compromise. The design and security of SPHINX is based on the device-enhanced PAKE model of Jarecki et al. that provides the theoretical basis for this construction and is backed by rigorous cryptographic proofs of security. While SPHINX is suitable for different device and online platforms, in this paper, we report on its concrete instantiation on smartphones given their popularity and trustworthiness as password managers (or even two-factor authentication). We present the design, implementation and performance evaluation of SPHINX, offering prototype browser plugins, smartphone apps and transparent device-client communication. Based on our inspection analysis, the overall user experience of SPHINX improves upon current managers. We also report on a lab-based usability study of SPHINX, which indicates that users' perception of SPHINX security and usability is high and satisfactory when compared to regular password-based authentication. Finally, we discuss how SPHINX may be extended to an online service for the purpose of back-up or as an independent password manager." @default.
- W2735788045 created "2017-07-21" @default.
- W2735788045 creator A5045531459 @default.
- W2735788045 creator A5059730489 @default.
- W2735788045 creator A5074744414 @default.
- W2735788045 creator A5076825881 @default.
- W2735788045 date "2017-06-01" @default.
- W2735788045 modified "2023-10-18" @default.
- W2735788045 title "SPHINX: A Password Store that Perfectly Hides Passwords from Itself" @default.
- W2735788045 cites W1501932514 @default.
- W2735788045 cites W1540780277 @default.
- W2735788045 cites W1884689072 @default.
- W2735788045 cites W1889757464 @default.
- W2735788045 cites W1959803714 @default.
- W2735788045 cites W1985816353 @default.
- W2735788045 cites W2030993695 @default.
- W2735788045 cites W2037202491 @default.
- W2735788045 cites W2100783932 @default.
- W2735788045 cites W2110495618 @default.
- W2735788045 cites W2123544182 @default.
- W2735788045 cites W2125011234 @default.
- W2735788045 cites W2139842203 @default.
- W2735788045 cites W2145994642 @default.
- W2735788045 cites W2148327104 @default.
- W2735788045 cites W2149929743 @default.
- W2735788045 cites W2406790903 @default.
- W2735788045 cites W27238938 @default.
- W2735788045 doi "https://doi.org/10.1109/icdcs.2017.64" @default.
- W2735788045 hasPublicationYear "2017" @default.
- W2735788045 type Work @default.
- W2735788045 sameAs 2735788045 @default.
- W2735788045 citedByCount "14" @default.
- W2735788045 countsByYear W27357880452019 @default.
- W2735788045 countsByYear W27357880452020 @default.
- W2735788045 countsByYear W27357880452021 @default.
- W2735788045 countsByYear W27357880452022 @default.
- W2735788045 countsByYear W27357880452023 @default.
- W2735788045 crossrefType "proceedings-article" @default.
- W2735788045 hasAuthorship W2735788045A5045531459 @default.
- W2735788045 hasAuthorship W2735788045A5059730489 @default.
- W2735788045 hasAuthorship W2735788045A5074744414 @default.
- W2735788045 hasAuthorship W2735788045A5076825881 @default.
- W2735788045 hasConcept C109297577 @default.
- W2735788045 hasConcept C23875713 @default.
- W2735788045 hasConcept C3847113 @default.
- W2735788045 hasConcept C38652104 @default.
- W2735788045 hasConcept C41008148 @default.
- W2735788045 hasConcept C70530487 @default.
- W2735788045 hasConcept C89479133 @default.
- W2735788045 hasConcept C98705547 @default.
- W2735788045 hasConceptScore W2735788045C109297577 @default.
- W2735788045 hasConceptScore W2735788045C23875713 @default.
- W2735788045 hasConceptScore W2735788045C3847113 @default.
- W2735788045 hasConceptScore W2735788045C38652104 @default.
- W2735788045 hasConceptScore W2735788045C41008148 @default.
- W2735788045 hasConceptScore W2735788045C70530487 @default.
- W2735788045 hasConceptScore W2735788045C89479133 @default.
- W2735788045 hasConceptScore W2735788045C98705547 @default.
- W2735788045 hasLocation W27357880451 @default.
- W2735788045 hasOpenAccess W2735788045 @default.
- W2735788045 hasPrimaryLocation W27357880451 @default.
- W2735788045 hasRelatedWork W2017283799 @default.
- W2735788045 hasRelatedWork W2079990687 @default.
- W2735788045 hasRelatedWork W2097945858 @default.
- W2735788045 hasRelatedWork W3013108623 @default.
- W2735788045 hasRelatedWork W3131491961 @default.
- W2735788045 hasRelatedWork W4283835082 @default.
- W2735788045 hasRelatedWork W4321600778 @default.
- W2735788045 hasRelatedWork W1844709308 @default.
- W2735788045 hasRelatedWork W2185274381 @default.
- W2735788045 hasRelatedWork W2257115038 @default.
- W2735788045 isParatext "false" @default.
- W2735788045 isRetracted "false" @default.
- W2735788045 magId "2735788045" @default.
- W2735788045 workType "article" @default.