Skip to main content
Journal cover image

Delegation of cryptographic servers for capture-resilient devices

Publication ,  Journal Article
MacKenzie, P; Reiter, MK
Published in: Distributed Computing
December 1, 2003

A device that performs private key operations (signatures or decryptions), and whose private key operations are protected by a password, can be immunized against offline dictionary attacks in case of capture by forcing the device to confirm a password guess with a designated remote server in order to perform a private key operation. Recent proposals for achieving this allow untrusted servers and require no server initialization per device. In this paper we extend these proposals to enable dynamic delegation from one server to another; i.e., the device can subsequently use the second server to secure its private key operations. One application is to allow a user who is traveling to a foreign country to temporarily delegate to a server local to that country the ability to confirm password guesses and aid the user's device in performing private key operations, or in the limit, to temporarily delegate this ability to a token in the user's possession, Another application is proactive security for the device's private key, i.e., proactive updates to the device and servers to eliminate any threat of offline password guessing attacks due to previously compromised servers.

Duke Scholars

Published In

Distributed Computing

DOI

ISSN

0178-2770

Publication Date

December 1, 2003

Volume

16

Issue

4

Start / End Page

307 / 327

Related Subject Headings

  • Computation Theory & Mathematics
  • 0805 Distributed Computing
 

Citation

APA
Chicago
ICMJE
MLA
NLM
MacKenzie, P., & Reiter, M. K. (2003). Delegation of cryptographic servers for capture-resilient devices. Distributed Computing, 16(4), 307–327. https://doi.org/10.1007/s00446-003-0098-4
MacKenzie, P., and M. K. Reiter. “Delegation of cryptographic servers for capture-resilient devices.” Distributed Computing 16, no. 4 (December 1, 2003): 307–27. https://doi.org/10.1007/s00446-003-0098-4.
MacKenzie P, Reiter MK. Delegation of cryptographic servers for capture-resilient devices. Distributed Computing. 2003 Dec 1;16(4):307–27.
MacKenzie, P., and M. K. Reiter. “Delegation of cryptographic servers for capture-resilient devices.” Distributed Computing, vol. 16, no. 4, Dec. 2003, pp. 307–27. Scopus, doi:10.1007/s00446-003-0098-4.
MacKenzie P, Reiter MK. Delegation of cryptographic servers for capture-resilient devices. Distributed Computing. 2003 Dec 1;16(4):307–327.
Journal cover image

Published In

Distributed Computing

DOI

ISSN

0178-2770

Publication Date

December 1, 2003

Volume

16

Issue

4

Start / End Page

307 / 327

Related Subject Headings

  • Computation Theory & Mathematics
  • 0805 Distributed Computing