Memory-Demanding Password Scrambling

Memory-Demanding Password Scrambling
复制标题

DOI:
10.1007/978-3-662-45608-8_16
复制
发表时间:
2014-12
期刊:
--
影响因子:
--
通讯作者:
C. Forler;S. Lucks;Jakob Wenzel
C. Forler;S. Lucks;Jakob Wenzel
中科院分区:
其他
文献类型:
--
作者:
C. Forler;S. Lucks;Jakob Wenzel

文献摘要

被引文献

相似文献

大多数常见的密码加扰器通过“密钥拉伸”来阻止密码猜测攻击,例如,通过多次迭代加密散列函数。随着廉价和大规模并行的现成硬件的日益可用性,迭代哈希函数变得越来越不有用。为了防御基于此类硬件的攻击,可以利用它们在每个单核的快速内存量方面的限制。第一个考虑到这一点的密码加密器是scrypt。在本文中,我们安装一个缓存定时攻击scrypt利用其密码相关的内存访问模式。此外,我们表明,它是可以应用一个有效的密码过滤器的恶意垃圾收集器的基础上的scrypt。作为一种补救措施,我们提出了一种新的密码扰码器称为Catena,它提供了一个密码独立的内存访问模式和抵抗垃圾收集器攻击。此外,用这里引入的(G,λ)-DBH操作来证明的链满足称为λ-记忆-硬度的特定时间-记忆折衷,即,仅使用1/b的内存量,计算密码散列所需的时间增加了b λ倍。最后,我们介绍了一个更有效的实例化的Catenbased上的位反转图。
Most of the common password scramblers hinder password-guessing attacks by “key stretching”, e.g., by iterating a cryptographic hash function many times. With the increasing availability of cheap and massively parallel off-the-shelf hardware, iterating a hash function becomes less and less useful. To defend against attacks based on such hardware, one can exploit their limitations regarding to the amount of fast memory for each single core. The first password scrambler taking this into account was scrypt. In this paper we mount a cache-timing attack on scrypt by exploiting its password-dependent memory-access pattern. Furthermore, we show that it is possible to apply an efficient password filter for scrypt based on a malicious garbage collector. As a remedy, we present a novel password scrambler calledCatenawhich provides both a password-independent memory-access pattern and resistance against garbage-collector attacks. Furthermore,Catenainstantiated with the here introduced (G,λ)-DBH operation satisfies a certain time-memory tradeoff calledλ-memory-hardness, i.e., using only 1/bthe amount of memory, the time necessary to compute the password hash is increased by a factor ofbλ. Finally, we introduce a more efficient instantiation ofCatenabased on a bit-reversal graph.