Feb. 5, 2024, 8:10 p.m. | Emma Dauterman Danny Lin Henry Corrigan-Gibbs David Mazi\`eres

cs.CR updates on arXiv.org arxiv.org

Credential compromise is hard to detect and hard to mitigate. To address this problem, we present larch, an accountable authentication framework with strong security and privacy properties. Larch protects user privacy while ensuring that the larch log server correctly records every authentication. Specifically, an attacker who compromises a user's device cannot authenticate without creating evidence in the log, and the log cannot learn which web service (relying party) the user is authenticating to. To enable fast adoption, larch is backwards-compatible …

address attacker authentication compromise credential credential compromise cs.cr detect framework hard log login privacy problem protection records security server system user privacy

