Secure Remote Password protocol
Cryptographic protocol for identification
The Secure Remote Password protocol (SRP) is an augmented password-authenticated key exchange (PAKE) protocol, specifically designed to work around existing patents. Like all PAKE protocols, an eavesdropper or man in the middle cannot obtain enough information to be able to brute-force guess a password or apply a dictionary attack without further interactions with the parties for each guess.
Nº Q576988 ★
Common · Literature
Secure Remote Password protocol
Cryptographic protocol for identification
The Secure Remote Password protocol (SRP) is an augmented password-authenticated key exchange (PAKE) protocol, specifically designed to work around existing patents. Like all PAKE protocols, an eavesdropper or man in the middle cannot obtain enough information to be able to brute-force guess a password or apply a dictionary attack without further interactions with the parties for each guess.
Last price
—
Floor price
—
7-day median
—
30-day sales
0
30-day range
—
In circulation
0
Price history
median
low – high
sales
No sales in this period
Show table
| Date | median | Low | High | sales |
|---|
Sales history
- Last sale
- —
- 30-day average
- —
- 30-day low
- —
- 30-day high
- —
- Sales 7d
- 0
- Sales 30d
- 0
No sales yet.
Anonymous sales: no buyer or seller shown. Figures count player-to-player sales only.
From Wikipedia
The Secure Remote Password protocol (SRP) is an augmented password-authenticated key exchange (PAKE) protocol, specifically designed to work around existing patents. Like all PAKE protocols, an eavesdropper or man in the middle cannot obtain enough information to be able to brute-force guess a password or apply a dictionary attack without further interactions with the parties for each guess. Furthermore, being an augmented PAKE protocol, the server does not store password-equivalent data. This means that an attacker who steals the server data cannot masquerade as the client unless they first perform a brute force search for the password. In layman's terms, during SRP (or any other PAKE protocol) authentication, one party (the "client" or "user") demonstrates to another party (the "server") that they know the password, without sending the password itself nor any other information from which the password can be derived. The password never leaves the client and is unknown to the server. Furthermore, the server also needs to know about the password (but not the password itself) in order to instigate the secure connection. This means that the server also authenticates itself to the client which prevents phishing without reliance on the user parsing complex URLs. The only mathematically proven security property of SRP is that it is equivalent to Diffie-Hellman against a passive attacker. While mature and widely deployed, SRP is an older design with some variants showing subtle weaknesses; it is not UC‑secure, lacks resistance to all precomputation attacks, has weaker formal proofs, and offers no protection against certain modern attack models. For these reasons, SRP is now largely considered superseded. OPAQUE is the preferred augmented PAKE, while CPace or SPAKE2 are favored for balanced PAKE scenarios where both parties share the password.
Text: Wikipédia, CC BY-SA 4.0. ·
Related cards
-
P
Password Authentication Protocol
Password-based authentication protocol used by PPP or RADIUS
Nº Q959710 ★
Not listed
-
Secure Shell
Cryptographic network protocol for secure remote access
Nº Q170460 ★★★★
Not listed
-
Remote procedure call
Mechanism to allow software to execute a remote procedure
Nº Q62270 ★★★
Not listed
-
S
Strong cryptography
Term applied to cryptographic systems that are highly resistant to cryptanalysis.
Nº Q4241181 ★★
Not listed
-
R
Remote Desktop Protocol
Proprietary protocol that can provide a user with the graphical interface of another, remote, computer
Nº Q49150 ★★★
Not listed
-
C
Common Address Redundancy Protocol
Computer networking protocol; allows multiple hosts on the same local area network to share IP addresses; provides failover redundancy, especially with firewalls and routers
Nº Q868562 ★
Not listed