In
Proc. 2007
IEEE Symposium on Security and Privacy (Oakland 2007), pp. 92-97.
We analyze the encryption
schemes used in Kerberos. Although, most of the options suggested in
the current version
are sound for which we provide security proofs under standard
assumptions, we point out flaws in the so called “General
Profile” and suggest easy to implement modifications to
provably fix them. For a widely deployed protocol like
Kerberos, such provable security guarantees can go a long way in the
standardization process.
In Computers
& Security,
vol. 25, no. 2, pp. 114-120, 2006.
In this paper, we
propose an
authentication protocol which is easy to implement without any
infrastructural changes and yet prevents online dictionary attacks. Our
protocol uses only one way hash functions and eliminates online
dictionary attacks by implementing a challenge-response system. The
protocol is perfectly stateless and thus less vulnerable to denial of
service (DoS) attacks.
In Proc.
International Conference on Information Technology: Coding and Computing (ITCC 2005), pp. 739-744.
This is the conference
version of the paper "A New Protocol to Counter Online Dictionary
Attacks".