Why Crypto Authentication?
Same key is also used to sign e-mail
- User has only one passphrase to remember.
- Existing key management infrastructure
Strong user authentication.
- Expensive Crypto operations are OK
- Random challenge prevents replay attack
User maintains all secret material
- Compromised server results in limited damage