University of Surrey

Test tubes in the lab Research in the ATI Dance Research

Zero-Knowledge Password Policy Checks and Verifier-Based PAKE

Kiefer, F and Manulis, M (2014) Zero-Knowledge Password Policy Checks and Verifier-Based PAKE In: 19th European Symposium on Research in Computer Security, 2014-09-07 - 2014-09-11, Wroclaw, Poland.

KiMa_ESORICS14.pdf - ["content_typename_UNSPECIFIED" not defined]
Available under License : See the attached licence file.

Download (504kB) | Preview
PDF (licence)
Available under License : See the attached licence file.

Download (33kB) | Preview


Zero-Knowledge Password Policy Checks (ZKPPC), introduced in this work, enable blind registration of client passwords at remote servers, i.e., client passwords are never transmitted to the servers. This eliminates the need for trusting servers to securely process and store client passwords. A ZKPPC protocol, executed as part of the registration procedure, allows clients to further prove compliance of chosen passwords with respect to password policies defined by the servers. The main benefit of ZKPPC-based password registration is that it guarantees that registered passwords never appear in clear on the server side. At the end of the registration phase the server only receives and stores some verification information that can later be used for authentication in a suitable Verifier-based Password Authenticated Key Exchange (VPAKE) protocol. We give general and concrete constructions of ZKPPC protocols and suitable VPAKE protocols for ASCII-based passwords and policies that are commonly used on the web. To this end we introduce a reversible mapping of ASCII characters to integers that can be used to preserve the structure of the password string and a new randomized password hashing scheme for ASCII-based passwords.

Item Type: Conference or Workshop Item (Conference Paper)
Divisions : Faculty of Engineering and Physical Sciences > Computing Science
Authors :
Date : 2014
Identification Number : 10.1007/978-3-319-11212-1
Contributors :
Additional Information : The original publication is available at
Depositing User : Symplectic Elements
Date Deposited : 17 Feb 2015 16:50
Last Modified : 17 Feb 2015 16:50

Actions (login required)

View Item View Item


Downloads per month over past year

Information about this web site

© The University of Surrey, Guildford, Surrey, GU2 7XH, United Kingdom.
+44 (0)1483 300800