An Efficient Privacy-Preserving Scheme for Weak Password Collection in Internet of Things
摘要
Password-based authentication is widely applied in Internet of Things (IoT) to resist unauthorized access. However, choices of weak passwords, especially popular ones, might violate the privacy of users and lead to large-scale network attacks in IoT. To address the issue, we propose EAGER, an efficient privacy-preserving scheme for weak password collection in IoT. EAGER is mainly constructed on lightweight tools including secret sharing and symmetric encryption, which allows a service provider to identify popular passwords without disclosing unpopular ones in an efficient manner. Furthermore, passwords are hardened via multiple key servers during the collection to thwart offline dictionary guessing attacks.