{"id":{"repo_id":"unf","oai_identifier":"oai:digitalcommons.unf.edu:etd-1698"},"canonical_url":"https://search.dev.ndltd.org/etd/unf/oai:digitalcommons.unf.edu:etd-1698","repository":{"repo_id":"unf","name":"University of North Florida","base_url":"https://digitalcommons.unf.edu/do/oai/"},"display":{"title":"Vulnerabililty Analysis of Multi-Factor Authentication Protocols","abstract":"In this thesis, the author hypothesizes that the use of computationally intensive mathematical operations in password authentication protocols can lead to security vulnerabilities in those protocols. In order to test this hypothesis: 1. A generalized algorithm for cryptanalysis was formulated to perform a clogging attack (a formof denial of service) on protocols that use computationally intensive modular exponentiation to guarantee security. 2. This technique was then applied to cryptanalyze four recent password authentication protocols, to determine their susceptibility to the clogging attack. The protocols analyzed in this thesis differ in their usage of factors (smart cards, memory drives, etc.) or their method of communication (encryption, nonces, timestamps, etc.). Their similarity lies in their use of computationally intensivemodular exponentiation as amediumof authentication. It is concluded that the strengths of all the protocols studied in this thesis can be combined tomake each of the protocols secure from the clogging attack. The conclusion is supported by designing countermeasures for each protocol against the clogging attack.","abstract_html":"In this thesis, the author hypothesizes that the use of computationally intensive mathematical operations in password authentication protocols can lead to security vulnerabilities in those protocols. In order to test this hypothesis: 1. A generalized algorithm for cryptanalysis was formulated to perform a clogging attack (a formof denial of service) on protocols that use computationally intensive modular exponentiation to guarantee security. 2. This technique was then applied to cryptanalyze four recent password authentication protocols, to determine their susceptibility to the clogging attack. The protocols analyzed in this thesis differ in their usage of factors (smart cards, memory drives, etc.) or their method of communication (encryption, nonces, timestamps, etc.). Their similarity lies in their use of computationally intensivemodular exponentiation as amediumof authentication. It is concluded that the strengths of all the protocols studied in this thesis can be combined tomake each of the protocols secure from the clogging attack. The conclusion is supported by designing countermeasures for each protocol against the clogging attack.","abstract_has_math":false,"creators":["Garrett, Keith","Garrett, Keith A., 1960-"],"institution":"University of North Florida. School of Computing","degree_name":"Master of Science in Computer and Information Sciences (MS)","degree_level":null,"degree_discipline":null,"degree_department":null,"school":null,"contributors":["Dr. Swapnoneel Roy","Dr. Asai Asaithambi","Dr. Sandeep Reddivari","Dr. Anand Seetharam"],"advisors":[],"committee_chairs":[],"committee_members":[],"year":null,"date_issued":"","date_published":null,"updated_at":"2026-08-21T16:49:34Z","subjects":["clogging attack security","Information Security"],"languages":[],"rights":[],"rights_urls":["http://rightsstatements.org/vocab/InC/1.0/"],"identifier_entries":[]},"links":{"outbound_url":"https://digitalcommons.unf.edu/etd/715","outbound_label":"Repository record","outbound_source":"dc:identifier"},"source_record":{"url":"https://digitalcommons.unf.edu/do/oai/?verb=GetRecord&metadataPrefix=oai_etdms&identifier=oai%3Adigitalcommons.unf.edu%3Aetd-1698","prefix":"oai_etdms"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor","label":"Contributor","values":["Dr. Swapnoneel Roy","Dr. Asai Asaithambi","Dr. Sandeep Reddivari","Dr. Anand Seetharam"]},{"key":"dc:creator","label":"Author","values":["Garrett, Keith","Garrett, Keith A., 1960-"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date","label":"Dc Date","values":["2016-01-01T08:00:00Z"]},{"key":"dc:publisher","label":"Institution","values":["UNF Digital Commons"]},{"key":"dc:type","label":"Dc Type","values":["thesis","Master's Thesis"]},{"key":"thesis:degree_name","label":"Degree Name","values":["Master of Science in Computer and Information Sciences (MS)"]},{"key":"thesis:institution_name","label":"Thesis Institution Name","values":["University of North Florida. School of Computing"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["clogging attack security","Information Security"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:rights","label":"Dc Rights","values":["http://rightsstatements.org/vocab/InC/1.0/"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["https://digitalcommons.unf.edu/etd/715","https://digitalcommons.unf.edu/context/etd/article/1698/viewcontent/ETD1321PA.pdf"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["In this thesis, the author hypothesizes that the use of computationally intensive mathematical operations in password authentication protocols can lead to security vulnerabilities in those protocols. In order to test this hypothesis: 1. A generalized algorithm for cryptanalysis was formulated to perform a clogging attack (a formof denial of service) on protocols that use computationally intensive modular exponentiation to guarantee security. 2. This technique was then applied to cryptanalyze four recent password authentication protocols, to determine their susceptibility to the clogging attack. The protocols analyzed in this thesis differ in their usage of factors (smart cards, memory drives, etc.) or their method of communication (encryption, nonces, timestamps, etc.). Their similarity lies in their use of computationally intensivemodular exponentiation as amediumof authentication. It is concluded that the strengths of all the protocols studied in this thesis can be combined tomake each of the protocols secure from the clogging attack. The conclusion is supported by designing countermeasures for each protocol against the clogging attack."]},{"key":"dc:format","label":"Dc Format","values":["application/pdf"]},{"key":"dc:source","label":"Dc Source","values":["UNF Graduate Theses and Dissertations"]},{"key":"dc:title","label":"Title","values":["Vulnerabililty Analysis of Multi-Factor Authentication Protocols"]}]}],"canonical_facts":{"dc:contributor":["Dr. Swapnoneel Roy","Dr. Asai Asaithambi","Dr. Sandeep Reddivari","Dr. Anand Seetharam"],"dc:creator":["Garrett, Keith","Garrett, Keith A., 1960-"],"dc:date":["2016-01-01T08:00:00Z"],"dc:description":["In this thesis, the author hypothesizes that the use of computationally intensive mathematical operations in password authentication protocols can lead to security vulnerabilities in those protocols. In order to test this hypothesis: 1. A generalized algorithm for cryptanalysis was formulated to perform a clogging attack (a formof denial of service) on protocols that use computationally intensive modular exponentiation to guarantee security. 2. This technique was then applied to cryptanalyze four recent password authentication protocols, to determine their susceptibility to the clogging attack. The protocols analyzed in this thesis differ in their usage of factors (smart cards, memory drives, etc.) or their method of communication (encryption, nonces, timestamps, etc.). Their similarity lies in their use of computationally intensivemodular exponentiation as amediumof authentication. It is concluded that the strengths of all the protocols studied in this thesis can be combined tomake each of the protocols secure from the clogging attack. The conclusion is supported by designing countermeasures for each protocol against the clogging attack."],"dc:format":["application/pdf"],"dc:identifier":["https://digitalcommons.unf.edu/etd/715","https://digitalcommons.unf.edu/context/etd/article/1698/viewcontent/ETD1321PA.pdf"],"dc:publisher":["UNF Digital Commons"],"dc:rights":["http://rightsstatements.org/vocab/InC/1.0/"],"dc:source":["UNF Graduate Theses and Dissertations"],"dc:subject":["clogging attack security","Information Security"],"dc:title":["Vulnerabililty Analysis of Multi-Factor Authentication Protocols"],"dc:type":["thesis","Master's Thesis"],"thesis:degree_name":["Master of Science in Computer and Information Sciences (MS)"],"thesis:institution_name":["University of North Florida. School of Computing"]},"updated_at":"2026-08-21T16:49:34Z"}