arrow
Return

Verifiable Compromised Credential Checking

delete2026-07-20
delete0
PRE
AI
S
Song Mi
D
Ding Wang
G
Guanling Li
Z
Zhichen Li
DOI:10.1109/tifs.2026.3715105delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Password file breaches expose billions of credentials and enable notorious credential stuffing attacks, where the attacker exploits the leaked password to maliciously log into the victim’s applications. To mitigate this threat, compromised credential checking (C3) services, like HaveIBeenPwned (the first C3 service) and Google Password Checkup proposed by Thomas et al. (USENIX Security’19) are widely used. A C3 service allows clients to query whether their credentials (username or/and password) are exposed, without revealing the password. However, in existing C3 services, clients may receive unreliable query results because they all assume that the C3 server is fully trusted, and overlook a crucial security property: the verifiability of query results. For example, a malicious C3 server may respond that an exposed account has not been breached. To fill this gap, we propose the notion of verifiable C3 service (VerC3 for short), which equips current C3 services with query-result verifiability. The key challenge lies in how to determine whether the C3 server has honestly responded to the client’s query and faithfully updated the breached password records. We reveal that the verifiability problem inherently cannot be solved in the single-server setting. Based on this finding, our VerC3 is built in the two-server setting. Breached password records are signed by the data owner and stored by the online server. We define VerC3 as a suite of protocols that meet 11 desirable properties and build a simple, secure, and efficient instance, called Have I Really Been Pwned (HIRBP). We develop a prototype of HIRBP to show its practicality: It takes the client 136.91 ms to finish a query on a common PC, with a total bandwidth of 86 KB. In particular, we provide so far the most comprehensive empirical evaluation of C3 services against both online guessing attacks and breach extraction attacks, using 1.4 billion real-world passwords. We believe this work takes a substantial step toward reliable C3 services.
Keywords:
Password authentication
compromised credential checking
query verifiability
credential stuffing attacks

Journal

IEEE Transactions on Information Forensics and Security cover
IEEE Transactions on Information Forensics and Security
IF:
8
Papers:
5.2K
Citations:
2.3W

Organization

N
nankai university
Scholars:
4.7W
Papers: 3.2W
Citations: 74