{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,9]],"date-time":"2026-01-09T21:56:44Z","timestamp":1767995804797,"version":"3.49.0"},"reference-count":0,"publisher":"Universitatsbibliothek der Ruhr-Universitat Bochum","issue":"4","license":[{"start":{"date-parts":[[2024,12,18]],"date-time":"2024-12-18T00:00:00Z","timestamp":1734480000000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["ToSC"],"abstract":"<jats:p>Hash chain based password systems are a useful way to guarantee authentication with one-time passwords. The core idea dates back to Lamport, and is specified in RFC 1760 as S\/Key. At CCS 2017, Kogan et al. introduced T\/Key, an improved password system where one-time passwords are only valid for a limited time period. They proved security of their construction in the random oracle model under a basic modeling of the adversary. In this work, we make various advances in the analysis and instantiation of hash chain based password systems. Firstly, we describe a slight abstraction called U\/Key that allows for more flexibility in the instantiation and analysis, and we develop a security model that refines the adversarial strength into offline and online complexity, that can be used beyond the random oracle model, and that allows to argue multi-user security directly. Secondly, we derive a new security proof of U\/Key in the random oracle model, as well as dedicated and tighter security proofs of U\/Key instantiated with a sponge construction and a truncated permutation. These dedicated security proofs, in turn, solve a problem of understanding the preimage resistance of a cascaded evaluation of the sponge construction. When applied to T\/Key, these results improve significantly over the earlier results: whereas the originally suggested instantiation using SHA-256 uses a compression function that maps 768 bits into 256 bits, with a truncated permutation construction one can generically achieve 128 bits of security already with a permutation of size 256 bits.<\/jats:p>","DOI":"10.46586\/tosc.v2024.i4.249-286","type":"journal-article","created":{"date-parts":[[2024,12,18]],"date-time":"2024-12-18T12:50:22Z","timestamp":1734526222000},"page":"249-286","source":"Crossref","is-referenced-by-count":2,"title":["Permutation-Based Hash Chains with Application to Password Hashing"],"prefix":"10.46586","volume":"2024","author":[{"given":"Charlotte","family":"Lefevre","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Bart","family":"Mennink","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"25480","published-online":{"date-parts":[[2024,12,18]]},"container-title":["IACR Transactions on Symmetric Cryptology"],"original-title":[],"link":[{"URL":"https:\/\/ojs.ub.rub.de\/index.php\/ToSC\/article\/download\/11955\/11822","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/ojs.ub.rub.de\/index.php\/ToSC\/article\/download\/11955\/11822","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,12,18]],"date-time":"2024-12-18T12:50:32Z","timestamp":1734526232000},"score":1,"resource":{"primary":{"URL":"https:\/\/ojs.ub.rub.de\/index.php\/ToSC\/article\/view\/11955"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,12,18]]},"references-count":0,"journal-issue":{"issue":"4","published-online":{"date-parts":[[2024,12,18]]}},"URL":"https:\/\/doi.org\/10.46586\/tosc.v2024.i4.249-286","relation":{},"ISSN":["2519-173X"],"issn-type":[{"value":"2519-173X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,12,18]]}}}