3 ms·
https://www.usenix.org/legacy/event/hotsec08/tech/full_papers/clark/clark_html/ https://www.usenix.org/legacy/event/hotsec08/tech/full_paper... 3.1 Security A
by monochr 12y ago
https://www.usenix.org/legacy/event/hotsec08/tech/full_papers/clark/clark_html/ https://www.usenix.org/legacy/event/hotsec08/tech/full_paper...
3.1 Security Assumptions
Our threat model is based on four pragmatic assumptions.
Kerckhoffs' principle: The details of the authentication system that is in place is public information and known to all participants, including Oscar. Alice and Bob retain a shared secret (e.g., a password or set of passwords) that is both private and the foundation upon which the security of the system rests.
Observational principle: Alice communicates with Bob over a semi-private channel that can be observed by Oscar prior to the password being secured (i.e., encrypted or hashed). Namely, Oscar can observe the password(s) used by Alice and could even enter in Alice's password himself, after coercing her into revealing it.
Iteration principle: Unless explicitly prevented by the underlying system, Oscar is not bound to a single instance of coercion against Alice. He may force Alice to authenticate multiple times. Combined with the observational principle (Assumption 2), Oscar can force Alice to use a different password each time.
Forced-randomization principle: Oscar can choose to eliminate any strategy Alice may employ through the order in which she reveals the passwords she knows. For example, Oscar may force Alice into writing down a set of passwords so that he can randomly choose the order in which to iterate through them. The assumption is that this option is available to Oscar, not that he will necessarily employ it.