Efficient Password Multicast Authentication
P. Gayathri, A. Jeyamathi · 2014
This paper contain secure- password authentication involve third party. The previous methods focus on two party authentications who share the password. In the previous method is week against dictionary attack. Our method provide single sign like previous method and also against for on/off-line dictionary attack. This method provides forward securacy and also reduces the damage of single point failure. The plaintext-equivalent is a piece of data, as the compromised password will not allow an adversary to hashed password, which can be used to obtain the same decrypt past sessions. Also, a compromised session level of access that the adversary gets when the key will not allow an adversary to find out a adversary gets the password. These authentication-key password. exchange protocols have been developed for two parties. Tolerating the compromise of a password file: For These cannot provide Single Sign on (SSO) feature in the this, a server must keep not plaintext-equivalent. distributed computing without modification. Avoiding or reducing the damage of the single point Kerberos, which provides SSO, is focused on a of failure: When KDC is compromised in Kerberos, all password-based authentication protocol evolving on-line users and all target servers have to change the trusted third parties. Kerberos is based on a symmetric password and the key. Also, all past session can be cryptosystem and maintains shared secret keys of entities decrypted. in the Key Distribution Center (KDC) (2). Therefore, the Providing different trust level of servers: The trusted Kerberos server must be extremely secure, as it represents third party should not provide any information about a single point of failure for the entire system and all password to target servers. entities. Moreover, Kerberos is fragile to off-line dictionary attacks and cannot provide forward secrecy. Secure Password Authentication for Distributed