Search engine for discovering works of Art, research articles, and books related to Art and Culture
ShareThis
Javascript must be enabled to continue!

PAKE on the Web

View through CrossRef
Unlike existing password authentication mechanisms on the web that use passwords for client-side authentication only, password-authenticated key exchange (PAKE) protocols provide mutual authentication. In this article, we present an architecture to integrate existing PAKE protocols to the web. Our integration design consists of the client-side part and the server-side part. First, we implement the PAKE client-side functionality with a web browser plug-in, which provides a secure implementation base. The plug-in has a log-in window that can be customized by a user when the plug-in is installed. By checking the user-specific information in a log-in window, an ordinary user can easily detect a fake log-in window created by mobile code. The server-side integration comprises a web interface and a PAKE server. After a successful PAKE mutual authentication, the PAKE plug-in receives a one-time ticket and passes it to the web browser. The web browser authenticates itself by presenting this ticket over HTTPS to the web server. The plug-in then fades away and subsequent web browsing remains the same as usual, requiring no extra user education. Our integration design supports centralized log-ins for web applications from different web sites, making it appropriate for digital identity management. A prototype is developed to validate our design. Since PAKE protocols use passwords for mutual authentication, we believe that the deployment of this design will significantly mitigate the risk of phishing attacks.
Title: PAKE on the Web
Description:
Unlike existing password authentication mechanisms on the web that use passwords for client-side authentication only, password-authenticated key exchange (PAKE) protocols provide mutual authentication.
In this article, we present an architecture to integrate existing PAKE protocols to the web.
Our integration design consists of the client-side part and the server-side part.
First, we implement the PAKE client-side functionality with a web browser plug-in, which provides a secure implementation base.
The plug-in has a log-in window that can be customized by a user when the plug-in is installed.
By checking the user-specific information in a log-in window, an ordinary user can easily detect a fake log-in window created by mobile code.
The server-side integration comprises a web interface and a PAKE server.
After a successful PAKE mutual authentication, the PAKE plug-in receives a one-time ticket and passes it to the web browser.
The web browser authenticates itself by presenting this ticket over HTTPS to the web server.
The plug-in then fades away and subsequent web browsing remains the same as usual, requiring no extra user education.
Our integration design supports centralized log-ins for web applications from different web sites, making it appropriate for digital identity management.
A prototype is developed to validate our design.
Since PAKE protocols use passwords for mutual authentication, we believe that the deployment of this design will significantly mitigate the risk of phishing attacks.

Related Results

Security Analysis of Password-based Authenticated Key Exchange Protocols
Security Analysis of Password-based Authenticated Key Exchange Protocols
Abstract Password-based cryptosystems commonly suffer from dictionary attacks because their security depends on low entropy passwords. It is ever challenging to design a pa...
NICE-PAKE: On the Security of KEM-Based PAKE Constructions without Ideal Ciphers
NICE-PAKE: On the Security of KEM-Based PAKE Constructions without Ideal Ciphers
We present the No IC Encryption (NICE)-PAKE, a (semi)-generic symmetric Password Authenticated Key Exchange (PAKE) framework providing a quantum-safe alternative for the Ideal Ciph...
Web Mining for Public E-Services Personalization
Web Mining for Public E-Services Personalization
Over the last decade, we have witnessed an explosive growth in the information available on the Web. Today, Web browsers provide easy access to myriad sources of text and multimedi...
Web Mining for Public E-Services Personalization
Web Mining for Public E-Services Personalization
Over the last decade, we have witnessed an explosive growth in the information available on the Web. Today, Web browsers provide easy access to myriad sources of text and multimedi...
EXAMINING LEXICO-SEMANTIC DIVERSITY IN PAKISTANI ENGLISH THROUGH NEWSPAPER CORPUS ANALYSIS
EXAMINING LEXICO-SEMANTIC DIVERSITY IN PAKISTANI ENGLISH THROUGH NEWSPAPER CORPUS ANALYSIS
The present paper studies the lexico-semantic features of Pakistani English (PakE) in newspapers as influenced by globalization and localized cultural practices (Manuel, 2021). Pak...
KONSTRUKSI SOSIAL DAN KESALAHPAHAMAN KONSTRUKSI DALAM IKLAN FREN SOBAT VERSI "NELPON PAKE FREN BAYARNYA PAKE DAUN"
KONSTRUKSI SOSIAL DAN KESALAHPAHAMAN KONSTRUKSI DALAM IKLAN FREN SOBAT VERSI "NELPON PAKE FREN BAYARNYA PAKE DAUN"
Pesan merupakan suatu kontruksi tanda yang melalui interaksinya dengan penerima menghasilkan makna, dan membaca adalah proses menemukan makna yang terjadi ketika pembaca berinterak...
Bringing Web 2.0 to web lectures
Bringing Web 2.0 to web lectures
PurposeAt many universities, web lectures have become an integral part of the e‐learning portfolio over the last few years. While many aspects of the technology involved, like auto...
A survey of semantic web (Web 3.0), its applications, challenges, future and its relation with Internet of things (IoT)
A survey of semantic web (Web 3.0), its applications, challenges, future and its relation with Internet of things (IoT)
The Semantic Web (Web 3.0) is an advancement of the existing web in which knowledge is given well-defined importance, allowing people and machines to operate better. The Semantic W...

Back to Top