2009 Annual Computer Security Applications Conference 2009
DOI: 10.1109/acsac.2009.27
|View full text |Cite
|
Sign up to set email alerts
|

On the Security of PAS (Predicate-Based Authentication Service)

Abstract: Abstract-Recently a new human authentication scheme called PAS (predicate-based authentication service) was proposed, which does not require the assistance of any supplementary device. The main security claim of PAS is to resist passive adversaries who can observe the whole authentication session between the human user and the remote server.In this paper we show that PAS is insecure against both brute force attack and a probabilistic attack. In particular, we show that its security against brute force attack w… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1
1
1

Citation Types

0
15
0

Year Published

2010
2010
2017
2017

Publication Types

Select...
5
2
1

Relationship

5
3

Authors

Journals

citations
Cited by 16 publications
(15 citation statements)
references
References 18 publications
0
15
0
Order By: Relevance
“…(0, 0), (13, 0), (0, 13), (13,13) We used Turk's method to compute a random point within a triangle [23]. Our simulation results suggest that increasing k makes the probability of success lower.…”
Section: Simulation Results For Attackmentioning
confidence: 99%
“…(0, 0), (13, 0), (0, 13), (13,13) We used Turk's method to compute a random point within a triangle [23]. Our simulation results suggest that increasing k makes the probability of success lower.…”
Section: Simulation Results For Attackmentioning
confidence: 99%
“…PAS uses different parts of the password for different login sessions and the user's responses are obfuscated by randomized challenge and response tables. In [31], Li et al show that part of the password can be revealed with a number of observations, thus leading to a degradation of the PAS scheme to a common OTP (one-timepassword) system but with worse usability.…”
Section: C(1125)≈2mentioning
confidence: 99%
“…In [47], the authors have re-examined the security claims of Predicate-based Authentication Service (PAS) and successfully indicated PAS was insecure against probabilistic attack and brute force attack. The PAS system claims security against three attacks: random guess, SAT (satisfiability solver) and brute force attacks that is highly over-estimated.…”
Section: B Review Of Non-otp Based Schemesmentioning
confidence: 99%