Security Analysis of salt||password Hashes

Security Analysis of salt||password Hashes
复制标题

盐||密码哈希的安全分析

DOI:
--
复制
发表时间:
2012
期刊:
International Conference on Advanced Computer Science Applications and Technologies
影响因子:
--
通讯作者:
Praveen Gauravaram
Praveen Gauravaram
中科院分区:
--
文献类型:
--
作者:
Praveen Gauravaram

文献摘要

被引文献

相似文献

保护用于验证计算机系统和网络的密码是加密哈希函数最重要的应用之一。由于生日和字典攻击等预计算内存查找攻击应用在密码的哈希值上来查找密码,因此通常建议对盐和密码的组合应用哈希函数(表示为 salt||password)来防止这些攻击。在本文中,我们首次对盐||密码哈希应用进行安全分析。我们表明,当使用基于具有容易找到的固定点的压缩函数的散列函数来计算盐||密码散列时,这些散列容易受到预先计算的离线生日攻击。例如,此攻击适用于使用标准哈希函数(例如基于流行的 Davies-Meyer 压缩函数的 MD5、SHA-1、SHA-256 和 SHA-512)计算的盐||密码哈希值。此攻击暴露了此应用程序的一个微妙属性,即尽管提供盐可以防止攻击者找到密码,但在密码前面添加盐并不能阻止攻击者进行预先计算的生日攻击以伪造未知密码。在这次伪造攻击中,我们演示了使用相同的哈希值和盐为未知密码构建多个密码的可能性。有趣的是,使用 Davies-Meyer 哈希函数计算的密码||盐(即密码后缀的盐)哈希不易受到此攻击,这显示了哈希密码的前缀盐和后缀盐方法之间的第一个安全差距。
Protection of passwords used to authenticate computer systems and networks is one of the most important application of cryptographic hash functions. Due to the application of precomputed memory look up attacks such as birthday and dictionary attacks on the hash values of passwords to find passwords, it is usually recommended to apply hash function to the combination of both the salt and password, denoted salt||password, to prevent these attacks. In this paper, we present the first security analysis of salt||password hashing application. We show that when hash functions based on the compression functions with easily found fixed points are used to compute the salt||password hashes, these hashes are susceptible to precomputed offline birthday attacks. For example, this attack is applicable to the salt||password hashes computed using the standard hash functions such as MD5, SHA-1, SHA-256 and SHA-512 that are based on the popular Davies-Meyer compression function. This attack exposes a subtle property of this application that although the provision of salt prevents an attacker from finding passwords, salts prefixed to the passwords do not prevent an attacker from doing a precomputed birthday attack to forge an unknown password. In this forgery attack, we demonstrate the possibility of building multiple passwords for an unknown password for the same hash value and salt. Interestingly, password||salt (i.e. salts suffixed to the passwords) hashes computed using Davies-Meyer hash functions are not susceptible to this attack, showing the first security gap between the prefix-salt and suffix-salt methods of hashing passwords.