Passwords and Cryptwords: The Final Limits on Lengths

Passwords and Cryptwords: The Final Limits on Lengths
复制标题

DOI:
10.1145/3584318.3584324
复制
发表时间:
2022-10
期刊:
Proceedings of the 2022 New Security Paradigms Workshop
影响因子:
--
通讯作者:
Michael Clark;Kenneth R. Seamons
Michael Clark;Kenneth R. Seamons
中科院分区:
其他
文献类型:
--
作者:
Michael Clark;Kenneth R. Seamons

文献摘要

相似文献

计算机的速度一年比一年快;大脑则不然。与令牌和生物识别技术相比,密码和其他记忆凭证具有独特的可用性优势,因此我们希望设计能够保持用户可以记忆的长度的安全系统。有些密码主要受到在线攻击,并且很容易通过速率限制和锁定来防御。其他用于生成加密密钥的工具必须能够抵御离线攻击。我们创造了“密码”一词来区分这些密码和主要受到在线攻击的密码。如果受到速率限制和锁定的保护,身份验证密码不需要随着计算机变得更快而变得更长。使用密码密钥派生函数(pwKDF)(一类预先存在的加密算法),我们表明,尽管计算取得了进步,密码也可以保持相同的长度并保持其安全强度。我们通过定期更新 pwKDF 参数并从密码重新生成派生密钥来实现这一点。在无法有意义地重新生成派生密钥的情况下,例如档案数据或公共验证者,应选择密码长度以持续数据的生命周期。我们提供简单的方程式,最终用户和系统管理员可以使用这些方程式根据个人威胁模型确定最小分配的密码和密码长度。我们还展示了如何使用云计算提供商的功能来估计攻击者成本。一旦加密数据泄露,这些相同的方程给出了密码和秘密轮换的时间范围。由于这些方程不依赖于当前日期或当前硬件功能,因此它们表明,如果经常使用,尽管硬件有所改进,密码和密码长度仍可以保持不变。
Computers get faster every year; brains don’t. Passwords and other memorized credentials have unique usability advantages over tokens and biometrics, so we desire to design secure systems that maintain lengths that users can memorize. Some passwords are subject primarily to online attacks, and are simple to defend with rate limits and lockouts. Others, used to generate encryption keys, must be secure against offline attacks. We coin the term “cryptword” to distinguish these from passwords subject primarily to online attacks. Authentication passwords do not need to get longer as computers get faster, if protected by rate limits and lockouts. Using password key derivation functions (pwKDFs) — a class of preexisting cryptographic algorithms — we show that cryptwords can also remain the same length and maintain their security strength despite advances in computation. We achieve this by regularly updating the pwKDF parameters and regenerating the derived key from the cryptword. In cases where it is not possible to meaningfully regenerate the derived key, such as archival data or public verifiers, cryptword lengths should be chosen to last the lifetime of the data. We provide simple equations that end users and system administrators can use to determine minimal assigned password and cryptword lengths based on personal threat models. We also show how to use the capabilities of cloud computing providers to estimate attacker costs. These same equations give a timeframe for cryptword and secret rotation once the encrypted data leaks. Because these equations do not rely on the current date or current hardware capabilities, they show that if regularly used, password and cryptword lengths can remain constant despite improvements in hardware.