LNCS Homepage
ContentsAuthor IndexSearch

Client-Server Password Recovery

(Extended Abstract)

ukasz Chmielewski1, Jaap-Henk Hoepman1,2, and Peter van Rossum1

1Digital Security Group, Radboud University Nijmegen, The Netherlands
lukaszc@cs.ru.nl
jhh@cs.ru.nl
petervr@cs.ru.nl

2TNO Information and Communication Technology, The Netherlands
jaap-henk.hoepman@tno.nl

Abstract. Human memory is not perfect – people constantly memorize new facts and forget old ones. One example is forgetting a password, a common problem raised at IT help desks. We present several protocols that allow a user to automatically recover a password from a server using partial knowledge of the password. These protocols can be easily adapted to the personal entropy setting [7], where a user can recover a password only if he can answer a large enough subset of personal questions.

We introduce client-server password recovery methods, in which the recovery data are stored at the server, and the recovery procedures are integrated into the login procedures. These methods apply to two of the most common types of password based authentication systems. The security of these solutions is significantly better than the security of presently proposed password recovery schemes. For our protocols we propose a variation of threshold encryption [5, 8, 16] that might be of independent interest.

LNCS 5871, p. 861 ff.

Full article in PDF | BibTeX


lncs@springer.com
© Springer-Verlag Berlin Heidelberg 2009