Papers1 provider · 1 record
January 1, 2019· KTH Publication Database DiVA (KTH Royal Institute of Technology)
dissertation
Open access

Breaking and fixing the Zero-knowledge password policy checks protocol by Kiefer and Manulis

Authors:Anton Bäckström *

Abstract

Zero-knowledge password policy checks (ZKPPC) were introduced in Kiefer and Manulis’ report from 2014. The protocol aimed to solve the longstanding issue with servers requiring clients to provide their password in plain text to ensure its strength. Their protocol was intended to eliminate the need for users to trust the server to store and handle passwords correctly while simultaneously allowing the server to know that the registered password was strong enough. This thesis has investigated the soundness of the protocol by Kiefer and Manulis and will present three new zero-day vulnerabilities discovered in the process. The vulnerabilities allow a dishonest user to prove adherence to the policy for invalid passwords. Additionally, the thesis presents our new Proof of Inequality which prevents one of these vulnerabilities, as well as an extension for an incomplete part of the protocol. The two remaining zero-day vulnerabilities are weaknesses in the protocol left for future research.

Community

0 comments
Use Connect Wallet in the navigation

No discussion yet

Be the first to share a question or observation.