@inbook {IOPORT.05639353, author = {Boyen, Xavier}, title = {HPAKE: Password authentication secure against cross-site user impersonation.}, year = {2009}, booktitle = {Cryptology and network security. 8th international conference, CANS 2009, Kanazawa, Japan, December 12--14, 2009. Proceedings}, isbn = {978-3-642-10432-9}, pages = {279-298}, publisher = {Berlin: Springer}, doi = {10.1007/978-3-642-10433-6_19}, abstract = {Summary: We propose a new kind of asymmetric mutual authentication from passwords with stronger privacy against malicious servers, lest they be tempted to engage in ``cross-site user impersonation'' to each other. It enables a person to authenticate (with) arbitrarily many independent servers, over adversarial channels, using a memorable and reusable single short password. Beside the usual PAKE security guarantees, our framework goes to lengths to secure the password against brute-force cracking from privileged server information.}, identifier = {05639353}, }