{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,6]],"date-time":"2026-05-06T17:13:45Z","timestamp":1778087625739,"version":"3.51.4"},"publisher-location":"Cham","reference-count":40,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783032253163","type":"print"},{"value":"9783032253170","type":"electronic"}],"license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026]]},"DOI":"10.1007\/978-3-032-25317-0_5","type":"book-chapter","created":{"date-parts":[[2026,5,6]],"date-time":"2026-05-06T16:42:34Z","timestamp":1778085754000},"page":"128-158","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Two-Factor Authentication Can Harden Servers Against Offline Password Search"],"prefix":"10.1007","author":[{"given":"Xavier","family":"Boyen","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Stanislaw","family":"Jarecki","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Phillip","family":"Nazarian","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jiayu","family":"Xu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Tianyu","family":"Zheng","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2026,5,7]]},"reference":[{"key":"5_CR1","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"191","DOI":"10.1007\/978-3-540-30574-3_14","volume-title":"Topics in Cryptology \u2013 CT-RSA 2005","author":"M Abdalla","year":"2005","unstructured":"Abdalla, M., Pointcheval, D.: Simple password-based encrypted key exchange protocols. In: Menezes, A. (ed.) CT-RSA 2005. LNCS, vol. 3376, pp. 191\u2013208. Springer, Heidelberg (2005). https:\/\/doi.org\/10.1007\/978-3-540-30574-3_14"},{"issue":"1","key":"5_CR2","doi-asserted-by":"publisher","first-page":"53","DOI":"10.1007\/s003730200002","volume":"18","author":"N Alon","year":"2002","unstructured":"Alon, N., Hoory, S., Linial, N.: The Moore bound for irregular graphs. Graphs Comb. 18(1), 53\u201357 (2002)","journal-title":"Graphs Comb."},{"key":"5_CR3","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"139","DOI":"10.1007\/3-540-45539-6_11","volume-title":"Advances in Cryptology \u2014 EUROCRYPT 2000","author":"M Bellare","year":"2000","unstructured":"Bellare, M., Pointcheval, D., Rogaway, P.: Authenticated key exchange secure against dictionary attacks. In: Preneel, B. (ed.) EUROCRYPT 2000. LNCS, vol. 1807, pp. 139\u2013155. Springer, Heidelberg (2000). https:\/\/doi.org\/10.1007\/3-540-45539-6_11"},{"key":"5_CR4","doi-asserted-by":"crossref","unstructured":"Bellovin, S.M., Merritt, M.: Encrypted key exchange: Password-based protocols secure against dictionary attacks. In: 1992 IEEE Symposium on Security and Privacy, pp. 72\u201384. IEEE Computer Society Press (1992)","DOI":"10.1109\/RISP.1992.213269"},{"key":"5_CR5","unstructured":"Benhamouda, F., Pointcheval, D.: Verifier-based password-authenticated key exchange: new models and constructions. Cryptology ePrint Archive, Report 2013\/833 (2013)"},{"key":"5_CR6","doi-asserted-by":"crossref","unstructured":"Bonneau, J.: The science of guessing: analyzing an anonymized corpus of 70 million passwords. In: Proceedings of the 2012 IEEE Symposium on Security and Privacy, SP 2012, pp. 538\u2013552, USA. IEEE Computer Society (2012)","DOI":"10.1109\/SP.2012.49"},{"key":"5_CR7","unstructured":"Boyen, X., Jarecki, S., Nazarian, P., Xu, J., Zheng, T.: Two-factor authentication can harden servers against offline password search. Cryptology ePrint Archive, Paper 2026\/317 (2026)"},{"key":"5_CR8","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"156","DOI":"10.1007\/3-540-45539-6_12","volume-title":"Advances in Cryptology \u2014 EUROCRYPT 2000","author":"V Boyko","year":"2000","unstructured":"Boyko, V., MacKenzie, P., Patel, S.: Provably secure password-authenticated key exchange using Diffie-Hellman. In: Preneel, B. (ed.) EUROCRYPT 2000. LNCS, vol. 1807, pp. 156\u2013171. Springer, Heidelberg (2000). https:\/\/doi.org\/10.1007\/3-540-45539-6_12"},{"key":"5_CR9","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"798","DOI":"10.1007\/978-3-030-26954-8_26","volume-title":"Advances in Cryptology \u2013 CRYPTO 2019","author":"T Bradley","year":"2019","unstructured":"Bradley, T., Jarecki, S., Xu, J.: Strong asymmetric PAKE based on trapdoor CKEM. In: Boldyreva, A., Micciancio, D. (eds.) CRYPTO 2019. LNCS, vol. 11694, pp. 798\u2013825. Springer, Cham (2019). https:\/\/doi.org\/10.1007\/978-3-030-26954-8_26"},{"key":"5_CR10","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"404","DOI":"10.1007\/11426639_24","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2005","author":"R Canetti","year":"2005","unstructured":"Canetti, R., Halevi, S., Katz, J., Lindell, Y., MacKenzie, P.: Universally composable password-based key exchange. In: Cramer, R. (ed.) EUROCRYPT 2005. LNCS, vol. 3494, pp. 404\u2013421. Springer, Heidelberg (2005). https:\/\/doi.org\/10.1007\/11426639_24"},{"key":"5_CR11","doi-asserted-by":"crossref","unstructured":"Chen, Y.-H., Lindell, Y.: Optimizing and implementing Fischlin\u2019s transform for UC-secure zero knowledge. IACR Commun. Cryptol. 1(2) (2024)","DOI":"10.62056\/a66chey6b"},{"key":"5_CR12","unstructured":"Christ, M., Baldimtsi, F., Chalkias, K.K., Maram, D., Roy, A., Wang, J.: SoK: Zero-knowledge range proofs. Cryptology ePrint Archive, Paper 2024\/430 (2024)"},{"key":"5_CR13","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"342","DOI":"10.1007\/978-3-540-30576-7_19","volume-title":"Theory of Cryptography","author":"R Cramer","year":"2005","unstructured":"Cramer, R., Damg\u00e5rd, I., Ishai, Y.: Share conversion, pseudorandom secret-sharing and applications to secure computation. In: Kilian, J. (ed.) TCC 2005. LNCS, vol. 3378, pp. 342\u2013362. Springer, Heidelberg (2005). https:\/\/doi.org\/10.1007\/978-3-540-30576-7_19"},{"key":"5_CR14","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"150","DOI":"10.1007\/3-540-46885-4_17","volume-title":"Advances in Cryptology \u2014 EUROCRYPT \u201989","author":"C Cr\u00e9peau","year":"1990","unstructured":"Cr\u00e9peau, C.: Verifiable disclosure of secrets and applications (abstract). In: Quisquater, J.-J., Vandewalle, J. (eds.) EUROCRYPT 1989. LNCS, vol. 434, pp. 150\u2013154. Springer, Heidelberg (1990). https:\/\/doi.org\/10.1007\/3-540-46885-4_17"},{"key":"5_CR15","doi-asserted-by":"crossref","unstructured":"Dos Santos, B.F., Gu, Y., Jarecki, S., Krawczyk, H.: Asymmetric PAKE with low computation and communication. In: Advances in Cryptology - EUROCRYPT 2022, pp. 127\u2013156 (2022)","DOI":"10.1007\/978-3-031-07085-3_5"},{"key":"5_CR16","unstructured":"Erd\u00f6s, P., Sachs, H.: Regul\u00e4re Graphen gegebener Taillenweite mit minimaler Knotenzahl. Wissenschaftliche Zeitschrift der Martin-Luther-Universit\u00e4t Halle-Wittenberg Math.-Nat. XII(3), 251\u2013258 (1963)"},{"key":"5_CR17","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"152","DOI":"10.1007\/11535218_10","volume-title":"Advances in Cryptology \u2013 CRYPTO 2005","author":"M Fischlin","year":"2005","unstructured":"Fischlin, M.: Communication-efficient non-interactive proofs of knowledge with online extractors. In: Shoup, V. (ed.) CRYPTO 2005. LNCS, vol. 3621, pp. 152\u2013168. Springer, Heidelberg (2005). https:\/\/doi.org\/10.1007\/11535218_10"},{"key":"5_CR18","doi-asserted-by":"crossref","unstructured":"Ford, W., Kaliski, B.S.: Server-assisted generation of a strong secret from a password. In: 9th IEEE International Workshops on Enabling Technologies: Infrastructure for Collaborative Enterprises (WETICE 2000), Gaithersburg, MD, USA, 4\u201316 June 2000, pp. 176\u2013180. IEEE Computer Society (2000)","DOI":"10.1109\/ENABL.2000.883724"},{"key":"5_CR19","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"303","DOI":"10.1007\/978-3-540-30576-7_17","volume-title":"Theory of Cryptography","author":"MJ Freedman","year":"2005","unstructured":"Freedman, M.J., Ishai, Y., Pinkas, B., Reingold, O.: Keyword search and oblivious pseudorandom functions. In: Kilian, J. (ed.) TCC 2005. LNCS, vol. 3378, pp. 303\u2013324. Springer, Heidelberg (2005). https:\/\/doi.org\/10.1007\/978-3-540-30576-7_17"},{"key":"5_CR20","doi-asserted-by":"crossref","unstructured":"F\u00fcredi, Z., Simonovits, M.: The history of degenerate (bipartite) extremal graph problems. In: Lov\u00e1sz, L., Ruzsa, I.Z., S\u00f3s, V.T. (eds.) Erd\u0151s Centennial, pp. 169\u2013264. Springer, Heidelberg (2013)","DOI":"10.1007\/978-3-642-39286-3_7"},{"key":"5_CR21","doi-asserted-by":"crossref","unstructured":"Garay, J.A., MacKenzie, P., Yang, K.: Efficient and universally composable committed oblivious transfer and applications. In: Theory of Cryptography, pp. 297\u2013316 (2004)","DOI":"10.1007\/978-3-540-24638-1_17"},{"key":"5_CR22","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"142","DOI":"10.1007\/11818175_9","volume-title":"Advances in Cryptology - CRYPTO 2006","author":"C Gentry","year":"2006","unstructured":"Gentry, C., MacKenzie, P., Ramzan, Z.: A method for making password-based key exchange resilient to server compromise. In: Dwork, C. (ed.) CRYPTO 2006. LNCS, vol. 4117, pp. 142\u2013159. Springer, Heidelberg (2006). https:\/\/doi.org\/10.1007\/11818175_9"},{"key":"5_CR23","doi-asserted-by":"crossref","unstructured":"Goldreich, O., Lindell, Y.: Session-key generation using human passwords only. In: Kilian, J. (ed.) CRYPTO 2001. LNCS, vol. 2139, pp. 408\u2013432. Springer, Heidelberg (2001)","DOI":"10.1007\/3-540-44647-8_24"},{"key":"5_CR24","doi-asserted-by":"crossref","unstructured":"Goldreich, O., Micali, S., Wigderson, A.: How to play any mental game or A completeness theorem for protocols with honest majority. In: Aho, A. (ed.) 19th ACM STOC, pp. 218\u2013229. ACM Press (1987)","DOI":"10.1145\/28395.28420"},{"key":"5_CR25","doi-asserted-by":"crossref","unstructured":"Gu, Y., Jarecki, S., Kedzior, P., Nazarian, P., Xu, J.: Threshold PAKE with security against compromise of all servers. In: Chung, K.-M., Sasaki, Y. (eds.) Advances in Cryptology - ASIACRYPT 2024, pp. 66\u2013100. Springer, Singapore (2025)","DOI":"10.1007\/978-981-96-0935-2_3"},{"key":"5_CR26","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"701","DOI":"10.1007\/978-3-030-84259-8_24","volume-title":"Advances in Cryptology \u2013 CRYPTO 2021","author":"Y Gu","year":"2021","unstructured":"Gu, Y., Jarecki, S., Krawczyk, H.: KHAPE: asymmetric PAKE from\u00a0key-hiding key exchange. In: Malkin, T., Peikert, C. (eds.) CRYPTO 2021. LNCS, vol. 12828, pp. 701\u2013730. Springer, Cham (2021). https:\/\/doi.org\/10.1007\/978-3-030-84259-8_24"},{"issue":"2","key":"5_CR27","first-page":"1","volume":"2019","author":"B Haase","year":"2019","unstructured":"Haase, B., Labrique, B.: AuCPace: efficient verifier-based PAKE protocol tailored for the IIoT. IACR TCHES 2019(2), 1\u201348 (2019)","journal-title":"IACR TCHES"},{"key":"5_CR28","doi-asserted-by":"crossref","unstructured":"Jablon, D.P.: Extended password key exchange protocols immune to dictionary attacks. In: 6th IEEE International Workshops on Enabling Technologies: Infrastructure for Collaborative Enterprises (WETICE 1997), pp. 248\u2013255, Cambridge, MA, USA, 18\u201320 June 1997. IEEE Computer Society (1997)","DOI":"10.1109\/ENABL.1997.630822"},{"key":"5_CR29","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"456","DOI":"10.1007\/978-3-319-78372-7_15","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2018","author":"S Jarecki","year":"2018","unstructured":"Jarecki, S., Krawczyk, H., Xu, J.: OPAQUE: an asymmetric PAKE protocol secure against pre-computation attacks. In: Nielsen, J.B., Rijmen, V. (eds.) EUROCRYPT 2018. LNCS, vol. 10822, pp. 456\u2013486. Springer, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-319-78372-7_15"},{"key":"5_CR30","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"97","DOI":"10.1007\/978-3-540-72540-4_6","volume-title":"Advances in Cryptology - EUROCRYPT 2007","author":"S Jarecki","year":"2007","unstructured":"Jarecki, S., Shmatikov, V.: Efficient two-party secure computation on committed inputs. In: Naor, M. (ed.) EUROCRYPT 2007. LNCS, vol. 4515, pp. 97\u2013114. Springer, Heidelberg (2007). https:\/\/doi.org\/10.1007\/978-3-540-72540-4_6"},{"key":"5_CR31","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"475","DOI":"10.1007\/3-540-44987-6_29","volume-title":"Advances in Cryptology \u2014 EUROCRYPT 2001","author":"J Katz","year":"2001","unstructured":"Katz, J., Ostrovsky, R., Yung, M.: Efficient password-authenticated key exchange using human-memorable passwords. In: Pfitzmann, B. (ed.) EUROCRYPT 2001. LNCS, vol. 2045, pp. 475\u2013494. Springer, Heidelberg (2001). https:\/\/doi.org\/10.1007\/3-540-44987-6_29"},{"key":"5_CR32","doi-asserted-by":"crossref","unstructured":"Kim, S., Lee, H., Seo, J.H.: Efficient zero-knowledge arguments in discrete logarithm setting: sublogarithmic proof or sublinear verifier. In: Agrawal, S., Lin, D. (eds.) Advances in Cryptology \u2013 ASIACRYPT 2022, pp. 403\u2013433 (2022)","DOI":"10.1007\/978-3-031-22966-4_14"},{"key":"5_CR33","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"385","DOI":"10.1007\/3-540-45708-9_25","volume-title":"Advances in Cryptology \u2014 CRYPTO 2002","author":"P MacKenzie","year":"2002","unstructured":"MacKenzie, P., Shrimpton, T., Jakobsson, M.: Threshold password-authenticated key exchange. In: Yung, M. (ed.) CRYPTO 2002. LNCS, vol. 2442, pp. 385\u2013400. Springer, Heidelberg (2002). https:\/\/doi.org\/10.1007\/3-540-45708-9_25"},{"key":"5_CR34","doi-asserted-by":"crossref","unstructured":"McQuoid, I., Rosulek, M., Xu, J.: How to obfuscate MPC inputs. In: Kiltz, E., Vaikuntanathan, V. (eds.) Theory of Cryptography, pp. 151\u2013180 (2022)","DOI":"10.1007\/978-3-031-22365-5_6"},{"key":"5_CR35","doi-asserted-by":"crossref","unstructured":"McQuoid, I., Xu, J.: An efficient strong asymmetric PAKE compiler instantiable from group actions. In: ASIACRYPT 2023, pp. 176\u2013207 (2023)","DOI":"10.1007\/978-981-99-8742-9_6"},{"issue":"2","key":"5_CR36","doi-asserted-by":"publisher","first-page":"231","DOI":"10.1145\/972639.972643","volume":"51","author":"M Naor","year":"2004","unstructured":"Naor, M., Reingold, O.: Number-theoretic constructions of efficient pseudo-random functions. J. ACM 51(2), 231\u2013262 (2004)","journal-title":"J. ACM"},{"key":"5_CR37","unstructured":"Radwan, R., Zejnilovic, S.: Password reuse is rampant: nearly half of observed user logins are compromised (2025). https:\/\/blog.cloudflare.com\/password-reuse-rampant-half-user-logins-compromised\/"},{"key":"5_CR38","doi-asserted-by":"crossref","unstructured":"Shirvanian, M., Jarecki, S., Saxena, N., Nathan, N.: Two-factor authentication resilient to server compromise using mix-bandwidth devices. In: 21st Annual Network and Distributed System Security Symposium, NDSS (2014)","DOI":"10.14722\/ndss.2014.23167"},{"key":"5_CR39","doi-asserted-by":"crossref","unstructured":"Shoup, V.: Lower bounds for discrete logarithms and related problems. In: Fumy, W. (ed.) Advances in Cryptology \u2014 EUROCRYPT 1997, pp. 256\u2013266 (1997)","DOI":"10.1007\/3-540-69053-0_18"},{"key":"5_CR40","doi-asserted-by":"crossref","unstructured":"Yao, A.C.-C.: Protocols for secure computations (extended abstract). In: 23rd FOCS, pp. 160\u2013164. IEEE Computer Society Press (1982)","DOI":"10.1109\/SFCS.1982.38"}],"container-title":["Lecture Notes in Computer Science","Advances in Cryptology \u2013 EUROCRYPT 2026"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-032-25317-0_5","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,6]],"date-time":"2026-05-06T16:42:45Z","timestamp":1778085765000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-032-25317-0_5"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026]]},"ISBN":["9783032253163","9783032253170"],"references-count":40,"URL":"https:\/\/doi.org\/10.1007\/978-3-032-25317-0_5","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026]]},"assertion":[{"value":"7 May 2026","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"EUROCRYPT","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Annual International Conference on the Theory and Applications of Cryptographic Techniques","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Rome","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Italy","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2026","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"10 May 2026","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"14 May 2026","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"45","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"eurocrypt2026","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/eurocrypt.iacr.org\/2026\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}