skip to main content
10.1145/1060745.1060815acmconferencesArticle/Chapter ViewAbstractPublication PageswwwConference Proceedingsconference-collections
Article

A convenient method for securely managing passwords

Published:10 May 2005Publication History

ABSTRACT

Computer users are asked to generate, keep secret, and recall an increasing number of passwords for uses including host accounts, email servers, e-commerce sites, and online financial services. Unfortunately, the password entropy that users can comfortably memorize seems insufficient to store unique, secure passwords for all these accounts, and it is likely to remain constant as the number of passwords (and the adversary's computational power) increases into the future. In this paper, we propose a technique that uses a strengthened cryptographic hash function to compute secure passwords for arbitrarily many accounts while requiring the user to memorize only a single short password. This mechanism functions entirely on the client; no server-side changes are needed. Unlike previous approaches, our design is both highly resistant to brute force attacks and nearly stateless, allowing users to retrieve their passwords from any location so long as they can execute our program and remember a short secret. This combination of security and convenience will, we believe, entice users to adopt our scheme. We discuss the construction of our algorithm in detail, compare its strengths and weaknesses to those of related approaches, and present Password Multiplier, an implementation in the form of an extension to the Mozilla Firefox web browser.

References

  1. Microsoft Passport service. http://www.passport.net.]]Google ScholarGoogle Scholar
  2. OpenSSL: The open source toolkit for SSL/TLS. http://www.openssl.org.]]Google ScholarGoogle Scholar
  3. Martín Abadi, T. Mark A. Lomas, and Roger Needham. Strengthening passwords. Technical Report 1997 - 033, 1997.]]Google ScholarGoogle Scholar
  4. Mihir Bellare, David Pointcheval, and Phillip Rogaway. Authenticated key exchange secure against dictionary attacks. In EUROCRYPT, pages 139--155, 2000.]] Google ScholarGoogle ScholarDigital LibraryDigital Library
  5. E. Felten, D. Balfanz, D. Dean, and D. Wallach. Web spoofing: An Internet con game. Proc. 20th National Information Systems Security Conference, 1997.]]Google ScholarGoogle Scholar
  6. Eran Gabber, Phillip B. Gibbons, Yossi Matias, and Alain J. Mayer. How to make personalized web browsing simple, secure, and anonymous. In Financial Cryptography, pages 17--32, 1997.]] Google ScholarGoogle ScholarDigital LibraryDigital Library
  7. Rosario Gennaro and Yehuda Lindell. A framework for password-based authenticated key exchange. In EUROCRYPT, pages 524--543, 2003.]] Google ScholarGoogle ScholarDigital LibraryDigital Library
  8. J. Jeff, Y. Alan, B. Ross, and A. Alasdair. The memorability and security of passwords -- some empirical results, 2000.]]Google ScholarGoogle Scholar
  9. Ian Jermyn, Alain Mayer, Fabian Monrose, Michael K. Reiter, and Aviel D. Rubin. The design and analysis of graphical passwords. 1999.]]Google ScholarGoogle Scholar
  10. Jonathan Katz, Rafail Ostrovsky, and Moti Yung. Efficient password-authenticated key exchange using human-memorable passwords. In EUROCRYPT '01: Proceedings of the International Conference on the Theory and Application of Cryptographic Techniques, pages 475--494. Springer-Verlag, 2001.]] Google ScholarGoogle ScholarDigital LibraryDigital Library
  11. J. Kelsey, B. Schneier, C. Hall, and D. Wagner. Secure applications of low-entropy keys. Lecture Notes in Computer Science, 1396:121--134, 1998.]] Google ScholarGoogle ScholarDigital LibraryDigital Library
  12. David P. Kormann and Aviel D. Rubin. Risks of the Passport single signon protocol. In Proc. 9th international World Wide Web conference on computer networks, pages 51--58. North-Holland Publishing Co., 2000.]] Google ScholarGoogle ScholarDigital LibraryDigital Library
  13. U. Manber. A simple scheme to make passwords based on one-way functions much harder to crack, 1996.]]Google ScholarGoogle Scholar
  14. Robert Morris and Ken Thompson. Password security: A case history. CACM, 22(11):594--597, 1979.]] Google ScholarGoogle ScholarDigital LibraryDigital Library
  15. Blake Ross, Collin Jackson, Nicholas Miyake, Dan Boneh, and John C. Mitchell. A browser plug-in solution to the unique password problem, 2005. Technical report, Stanford-SecLab-TR-2005-1.]]Google ScholarGoogle Scholar
  16. Bruce Schneier et al. Password Safe application. http://www.schneier.com/passsafe.html.]]Google ScholarGoogle Scholar
  17. Joe Smith. Password Safe cracker utility. http://members.aol.com/jpeschel3/recovery.htm.]]Google ScholarGoogle Scholar

Index Terms

  1. A convenient method for securely managing passwords

          Recommendations

          Comments

          Login options

          Check if you have access through your login credentials or your institution to get full access on this article.

          Sign in
          • Published in

            cover image ACM Conferences
            WWW '05: Proceedings of the 14th international conference on World Wide Web
            May 2005
            781 pages
            ISBN:1595930469
            DOI:10.1145/1060745

            Copyright © 2005 ACM

            Permission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for components of this work owned by others than ACM must be honored. Abstracting with credit is permitted. To copy otherwise, or republish, to post on servers or to redistribute to lists, requires prior specific permission and/or a fee. Request permissions from [email protected]

            Publisher

            Association for Computing Machinery

            New York, NY, United States

            Publication History

            • Published: 10 May 2005

            Permissions

            Request permissions about this article.

            Request Permissions

            Check for updates

            Qualifiers

            • Article

            Acceptance Rates

            Overall Acceptance Rate1,899of8,196submissions,23%

            Upcoming Conference

            WWW '24
            The ACM Web Conference 2024
            May 13 - 17, 2024
            Singapore , Singapore

          PDF Format

          View or Download as a PDF file.

          PDF

          eReader

          View online with eReader.

          eReader