{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,2,21]],"date-time":"2025-02-21T11:29:01Z","timestamp":1740137341270,"version":"3.37.3"},"reference-count":43,"publisher":"Springer Science and Business Media LLC","issue":"6","license":[{"start":{"date-parts":[[2016,9,21]],"date-time":"2016-09-21T00:00:00Z","timestamp":1474416000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2016,9,21]],"date-time":"2016-09-21T00:00:00Z","timestamp":1474416000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/501100001659","name":"Deutsche Forschungsgemeinschaft","doi-asserted-by":"publisher","award":["MA 4957"],"award-info":[{"award-number":["MA 4957"]}],"id":[{"id":"10.13039\/501100001659","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100000923","name":"Australian Research Council","doi-asserted-by":"publisher","award":["DP130104304"],"award-info":[{"award-number":["DP130104304"]}],"id":[{"id":"10.13039\/501100000923","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Int. J. Inf. Secur."],"published-print":{"date-parts":[[2016,11]]},"DOI":"10.1007\/s10207-016-0348-7","type":"journal-article","created":{"date-parts":[[2016,9,21]],"date-time":"2016-09-21T08:06:29Z","timestamp":1474445189000},"page":"597-620","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":9,"title":["Secure modular password authentication for the web using channel bindings"],"prefix":"10.1007","volume":"15","author":[{"given":"Mark","family":"Manulis","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Douglas","family":"Stebila","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Franziskus","family":"Kiefer","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Nick","family":"Denham","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2016,9,21]]},"reference":[{"key":"348_CR1","doi-asserted-by":"publisher","first-page":"35","DOI":"10.1145\/1128817.1128827","volume-title":"ASIACCS 06","author":"M Abdalla","year":"2006","unstructured":"Abdalla, M., Bresson, E., Chevassut, O., M\u00f6ller, B., Pointcheval, D.: Provably secure password-based authentication in TLS. In: Lin, F.C., Lee, D.T., Lin, B.S., Shieh, S., Jajodia, S. (eds.) ASIACCS 06, pp. 35\u201345. ACM Press, New York (2006)"},{"issue":"3\/4","key":"348_CR2","doi-asserted-by":"publisher","first-page":"284","DOI":"10.1504\/IJSN.2007.013181","volume":"2","author":"M Abdalla","year":"2007","unstructured":"Abdalla, M., Bresson, E., Chevassut, O., M\u00f6ller, B., Pointcheval, D.: Strong password-based authentication in TLS using the three-party group Diffie\u2013Hellman protocol. Int. J. Secur. Netw. 2(3\/4), 284\u2013296 (2007)","journal-title":"Int. J. Secur. Netw."},{"key":"348_CR3","series-title":"LNCS","first-page":"335","volume-title":"CT-RSA 2008","author":"M Abdalla","year":"2008","unstructured":"Abdalla, M., Catalano, D., Chevalier, C., Pointcheval, D.: Efficient two-party password-based key exchange protocols in the UC framework. In: Malkin, T. (ed.) CT-RSA 2008. LNCS, vol. 4964, pp. 335\u2013351. Springer, Heidelberg (2008)"},{"key":"348_CR4","series-title":"LNCS","first-page":"65","volume-title":"PKC 2005","author":"M Abdalla","year":"2005","unstructured":"Abdalla, M., Fouque, P.A., Pointcheval, D.: Password-based authenticated key exchange in the three-party setting. In: Vaudenay, S. (ed.) PKC 2005. LNCS, vol. 3386, pp. 65\u201384. Springer, Heidelberg (2005)"},{"key":"348_CR5","series-title":"LNCS","first-page":"191","volume-title":"CT-RSA 2005","author":"M Abdalla","year":"2005","unstructured":"Abdalla, M., Pointcheval, D.: Simple password-based encrypted key exchange protocols. In: Menezes, A. (ed.) CT-RSA 2005. LNCS, vol. 3376, pp. 191\u2013208. Springer, Heidelberg (2005)"},{"key":"348_CR6","doi-asserted-by":"crossref","unstructured":"Adrian, D., Bhargavan, K., Durumeric, Z., Gaudry, P., Green, M., Halderman, J.A., Heninger, N., Springall, D., Thom\u00e9, E., Valenta, L., VanderSloot, B., Wustrow, E., Zanella-B\u00e9guelin, S., Zimmermann, P.: Imperfect Forward Secrecy: How Diffie\u2013Hellman Fails in Practice (2015). https:\/\/weakdh.org\/","DOI":"10.1145\/2810103.2813707"},{"key":"348_CR7","unstructured":"AIST Research Center for Information Security: Mutual Authentication Protocol for HTTP. https:\/\/www.rcis.aist.go.jp\/special\/MutualAuth"},{"key":"348_CR8","doi-asserted-by":"crossref","unstructured":"Alexander, C., Goldberg, I.: Improved user authentication in Off-the-Record Messaging. In: Yu, T. (ed.) ACM Workshop on Privacy in Electronic Society (WPES) 2007, pp. 41\u201347. ACM Press, New York (2007)","DOI":"10.1145\/1314333.1314340"},{"key":"348_CR9","unstructured":"Altman, J., Williams, N., Zhu, L.: Channel Bindings for TLS. RFC 5929 (Proposed Standard) (2010). http:\/\/www.ietf.org\/rfc\/rfc5929.txt"},{"key":"348_CR10","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"139","DOI":"10.1007\/3-540-45539-6_11","volume-title":"EUROCRYPT 2000","author":"M Bellare","year":"2000","unstructured":"Bellare, M., Pointcheval, D., Rogaway, P.: Authenticated key exchange secure against dictionary attacks. In: Preneel, B. (ed.) EUROCRYPT 2000. LNCS, vol. 1807, pp. 139\u2013155. Springer, Heidelberg (2000)"},{"key":"348_CR11","unstructured":"Bellovin, S.M., Merritt, M.: Encrypted key exchange: password-based protocols secure against dictionary attacks. In: 1992 IEEE Symposium on Security and Privacy, pp. 72\u201384. IEEE Computer Society Press (1992)"},{"key":"348_CR12","doi-asserted-by":"crossref","first-page":"369","DOI":"10.1145\/2660267.2660286","volume-title":"ACM CCS 14","author":"F Bergsma","year":"2014","unstructured":"Bergsma, F., Dowling, B., Kohlar, F., Schwenk, J., Stebila, D.: Multi-ciphersuite security of the Secure Shell (SSH) protocol. In: Ahn, G.J., Yung, M., Li, N. (eds.) ACM CCS 14, pp. 369\u2013381. ACM Press, New York (2014)"},{"key":"348_CR13","doi-asserted-by":"crossref","unstructured":"Beurdouche, B., Bhargavan, K., Delignat-Lavaud, A., Fournet, C., Kohlweiss, M., Pironti, A., Strub, P.Y., Zinzindohoue, J.K.: A messy state of the union: taming the composite state machines of TLS. In: 2015 IEEE Symposium on Security and Privacy, pp. 535\u2013552. IEEE Computer Society Press (2015)","DOI":"10.1109\/SP.2015.39"},{"key":"348_CR14","doi-asserted-by":"crossref","unstructured":"Bhargavan, K., Delignat-Lavaud, A., Fournet, C., Pironti, A., Strub, P.Y.: Triple handshakes and cookie cutters: breaking and fixing authentication over TLS. In: 2014 IEEE Symposium on Security and Privacy, pp. 98\u2013113. IEEE Computer Society Press (2014)","DOI":"10.1109\/SP.2014.14"},{"key":"348_CR15","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"156","DOI":"10.1007\/3-540-45539-6_12","volume-title":"EUROCRYPT 2000","author":"V Boyko","year":"2000","unstructured":"Boyko, V., MacKenzie, P.D., Patel, S.: Provably secure password-authenticated key exchange using Diffie\u2013Hellman. In: Preneel, B. (ed.) EUROCRYPT 2000. LNCS, vol. 1807, pp. 156\u2013171. Springer, Heidelberg (2000)"},{"key":"348_CR16","doi-asserted-by":"publisher","first-page":"373","DOI":"10.1145\/2508859.2516748","volume-title":"ACM CCS 13","author":"C Brzuska","year":"2013","unstructured":"Brzuska, C., Smart, N.P., Warinschi, B., Watson, G.J.: An analysis of the EMV channel establishment protocol. In: Sadeghi, A.R., Gligor, V.D., Yung, M. (eds.) ACM CCS 13, pp. 373\u2013386. ACM Press, New York (2013)"},{"key":"348_CR17","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"404","DOI":"10.1007\/11426639_24","volume-title":"EUROCRYPT 2005","author":"R Canetti","year":"2005","unstructured":"Canetti, R., Halevi, S., Katz, J., Lindell, Y., MacKenzie, P.D.: Universally composable password-based key exchange. In: Cramer, R. (ed.) EUROCRYPT 2005. LNCS, vol. 3494, pp. 404\u2013421. Springer, Heidelberg (2005)"},{"key":"348_CR18","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"199","DOI":"10.1007\/978-3-642-33167-1_12","volume-title":"ESORICS 2012","author":"I Dacosta","year":"2012","unstructured":"Dacosta, I., Ahamad, M., Traynor, P.: Trust no one else: detecting MITM attacks against SSL\/TLS without third-parties. In: Foresti, S., Yung, M., Martinelli, F. (eds.) ESORICS 2012. LNCS, vol. 7459, pp. 199\u2013216. Springer, Heidelberg (2012)"},{"key":"348_CR19","doi-asserted-by":"publisher","first-page":"77","DOI":"10.1145\/1073001.1073009","volume-title":"Symposium on Usable Privacy and Security (SOUPS) 2005","author":"R Dhamija","year":"2005","unstructured":"Dhamija, R., Tygar, J.D.: The battle against phishing: dynamic security skins. In: Cranor, L.F., Zurko, M.E. (eds.) Symposium on Usable Privacy and Security (SOUPS) 2005, pp. 77\u201388. ACM Press, New York (2005)"},{"key":"348_CR20","unstructured":"Engler, J., Karlof, C., Shi, E., Song, D.: Is it too late for PAKE? In: Web 2.0 Security and Privacy (W2SP) (2009). http:\/\/w2spconf.com\/2009\/papers\/s4p1.pdf"},{"key":"348_CR21","doi-asserted-by":"crossref","unstructured":"Fleischhacker, N., Manulis, M., Azodi, A.: A modular framework for multi-factor authentication and key exchange. In: Security Standardisation Research (SSR 2014). LNCS, vol. 8893, pp. 190\u2013214. Springer (2014)","DOI":"10.1007\/978-3-319-14054-4_12"},{"key":"348_CR22","unstructured":"Franks, J., Hallam-Baker, P., Hostetler, J., Lawrence, S., Leach, P., Luotonen, A., Stewart, L.: HTTP Authentication: Basic and Digest Access Authentication. RFC 2617 (Draft Standard) (1999). http:\/\/www.ietf.org\/rfc\/rfc2617.txt , updated by RFC 7235"},{"key":"348_CR23","doi-asserted-by":"publisher","first-page":"387","DOI":"10.1145\/2508859.2516694","volume-title":"ACM CCS 13","author":"F Giesen","year":"2013","unstructured":"Giesen, F., Kohlar, F., Stebila, D.: On the security of TLS renegotiation. In: Sadeghi, A.R., Gligor, V.D., Yung, M. (eds.) ACM CCS 13, pp. 387\u2013398. ACM Press, New York (2013)"},{"key":"348_CR24","doi-asserted-by":"crossref","unstructured":"Hao, F., Ryan, P.Y.A.: Password authenticated key exchange by juggling. In: Security Protocols Workshop. LNCS, vol. 6615, pp. 159\u2013171. Springer (2008)","DOI":"10.1007\/978-3-642-22137-8_23"},{"key":"348_CR25","unstructured":"IEEE P1363.2: Standard Specifications for Password-Based Public-Key Cryptographic Techniques (2008). http:\/\/grouper.ieee.org\/groups\/1363\/passwdPK\/"},{"key":"348_CR26","unstructured":"International Organization for Standardization (ISO): ISO\/IEC 11770-4: Information Technology\u2014Security Techniques\u2014Key Management\u2014Part 4: Mechanisms Based on Weak Secrets (2006). http:\/\/www.iso.org\/iso\/home\/store\/catalogue_tc\/catalogue_detail.htm?csnumber=39723"},{"key":"348_CR27","unstructured":"ITU-T X.1035: Password-Authenticated Key Exchange (PAK) Protocol (2007). http:\/\/www.itu.int\/rec\/T-REC-X.1035-200702-I\/en"},{"key":"348_CR28","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"232","DOI":"10.1007\/978-3-642-17373-8_14","volume-title":"ASIACRYPT 2010","author":"T Jager","year":"2010","unstructured":"Jager, T., Kohlar, F., Sch\u00e4ge, S., Schwenk, J.: Generic compilers for authenticated key exchange. In: Abe, M. (ed.) ASIACRYPT 2010. LNCS, vol. 6477, pp. 232\u2013249. Springer, Heidelberg (2010)"},{"key":"348_CR29","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"273","DOI":"10.1007\/978-3-642-32009-5_17","volume-title":"CRYPTO 2012","author":"T Jager","year":"2012","unstructured":"Jager, T., Kohlar, F., Sch\u00e4ge, S., Schwenk, J.: On the security of TLS-DHE in the standard model. In: Safavi-Naini, R., Canetti, R. (eds.) CRYPTO 2012. LNCS, vol. 7417, pp. 273\u2013293. Springer, Heidelberg (2012)"},{"key":"348_CR30","unstructured":"Kohlar, F., Sch\u00e4ge, S., Schwenk, J.: On the security of TLS-DH and TLS-RSA in the standard model. Cryptology ePrint Archive, Report 2013\/367 (2013). http:\/\/eprint.iacr.org\/2013\/367"},{"key":"348_CR31","series-title":"LNCS","doi-asserted-by":"crossref","first-page":"429","DOI":"10.1007\/978-3-642-40041-4_24","volume-title":"CRYPTO 2013, Part I","author":"H Krawczyk","year":"2013","unstructured":"Krawczyk, H., Paterson, K.G., Wee, H.: On the security of the TLS protocol: a systematic analysis. In: Canetti, R., Garay, J.A. (eds.) CRYPTO 2013, Part I. LNCS, vol. 8042, pp. 429\u2013448. Springer, Heidelberg (2013)"},{"key":"348_CR32","unstructured":"Kwon, T.: Authentication and key agreement via memorable passwords. In: NDSS\u00a02001. The Internet Society (2001)"},{"key":"348_CR33","series-title":"LNCS","first-page":"1","volume-title":"ProvSec 2007","author":"BA LaMacchia","year":"2007","unstructured":"LaMacchia, B.A., Lauter, K., Mityagin, A.: Stronger security of authenticated key exchange. In: Susilo, W., Liu, J.K., Mu, Y. (eds.) ProvSec 2007. LNCS, vol. 4784, pp. 1\u201316. Springer, Heidelberg (2007)"},{"key":"348_CR34","doi-asserted-by":"crossref","unstructured":"Manulis, M., Stebila, D., Denham, N.: Secure Modular Password Authentication for the Web Using Channel Bindings. In: Security Standardisation Research (SSR 2014). LNCS, vol. 8893, pp. 167\u2013189. Springer (2014)","DOI":"10.1007\/978-3-319-14054-4_11"},{"key":"348_CR35","unstructured":"National Institute of Standards and Technology: Recommended Elliptic Curves for Federal Government Use (1999). http:\/\/csrc.nist.gov\/groups\/ST\/toolkit\/documents\/dss\/NISTReCur.pdf"},{"key":"348_CR36","unstructured":"Oiwa, Y., Takagi, H., Watanabe, H., Suzuki, H.: PAKE-based mutual HTTP authentication for preventing phishing attacks. In: Maarek, Y., Nejdl, W. (eds.) Proceedings of 18th International World Wide Web Conference (WWW) 2009, pp. 1143\u20131144. ACM (2009). http:\/\/www2009.org\/proceedings\/pdf\/p1143.pdf"},{"key":"348_CR37","unstructured":"Oiwa, Y., Watanabe, H., Takagi, H.: PAKE-based mutual HTTP authentication for preventing phishing attacks (2009). http:\/\/arxiv.org\/abs\/0911.5230"},{"key":"348_CR38","unstructured":"Oiwa, Y., Watanabe, H., Takagi, H., Kihara, B., Ioku, Y., Hayashi, T.: Mutual authentication protocol for HTTP (2012), Internet-Draft. http:\/\/tools.ietf.org\/html\/draft-oiwa-http-mutualauth-12"},{"key":"348_CR39","unstructured":"Rescorla, E.: Keying Material Exporters for Transport Layer Security (TLS). RFC 5705 (Proposed Standard) (2010). http:\/\/www.ietf.org\/rfc\/rfc5705.txt"},{"key":"348_CR40","doi-asserted-by":"crossref","unstructured":"Schechter, S.E., Dhamija, R., Ozment, A., Fischer, I.: The emperor\u2019s new security indicators. In: 2007 IEEE Symposium on Security and Privacy, pp. 51\u201365. IEEE Computer Society Press (2007)","DOI":"10.1109\/SP.2007.35"},{"key":"348_CR41","unstructured":"Sunshine, J., Egelman, S., Almuhimedi, H., Atri, N., Cranor, L.F.: Crying wolf: an empirical study of SSL warning effectiveness. In: USENIX Security 2009 (2009). http:\/\/www.usenix.org\/events\/sec09\/tech\/full_papers\/sunshine.pdf"},{"key":"348_CR42","unstructured":"Taylor, D., Wu, T., Mavrogiannopoulos, N., Perrin, T.: Using the Secure Remote Password (SRP) Protocol for TLS Authentication. RFC 5054 (Informational) (2007). http:\/\/www.ietf.org\/rfc\/rfc5054.txt"},{"key":"348_CR43","unstructured":"Wu, T.D.: The Secure Remote Password protocol. In: NDSS\u201998. The Internet Society (1998)"}],"container-title":["International Journal of Information Security"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s10207-016-0348-7.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s10207-016-0348-7\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s10207-016-0348-7.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,7,8]],"date-time":"2022-07-08T22:30:24Z","timestamp":1657319424000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s10207-016-0348-7"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2016,9,21]]},"references-count":43,"journal-issue":{"issue":"6","published-print":{"date-parts":[[2016,11]]}},"alternative-id":["348"],"URL":"https:\/\/doi.org\/10.1007\/s10207-016-0348-7","relation":{},"ISSN":["1615-5262","1615-5270"],"issn-type":[{"type":"print","value":"1615-5262"},{"type":"electronic","value":"1615-5270"}],"subject":[],"published":{"date-parts":[[2016,9,21]]},"assertion":[{"value":"21 September 2016","order":1,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}]}}