Client-Server Password Recovery (Extended Abstract)
{\L}ukasz Chmielewski, Jaap-Henk Hoepman, Peter van Rossum

TL;DR
This paper introduces new client-server password recovery protocols that leverage partial knowledge and threshold encryption, enhancing security and integrating seamlessly with existing authentication systems.
Contribution
It presents novel password recovery methods using threshold encryption, improving security and adaptability for common password-based authentication systems.
Findings
Protocols enable automatic password recovery with enhanced security.
Methods are adaptable to personal entropy and question-answering scenarios.
Security surpasses existing password recovery schemes.
Abstract
Human memory is not perfect - people constantly memorize new facts and forget old ones. One example is forgetting a password, a common problem raised at IT help desks. We present several protocols that allow a user to automatically recover a password from a server using partial knowledge of the password. These protocols can be easily adapted to the personal entropy setting, where a user can recover a password only if he can answer a large enough subset of personal questions. We introduce client-server password recovery methods, in which the recovery data are stored at the server, and the recovery procedures are integrated into the login procedures. These methods apply to two of the most common types of password based authentication systems. The security of these solutions is significantly better than the security of presently proposed password recovery schemes. Our protocols are based…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsUser Authentication and Security Systems · Cryptography and Data Security · Advanced Authentication Protocols Security
