Memory-Demanding Password Scrambling
Memory-Demanding Password Scrambling
复制标题
DOI:
10.1007/978-3-662-45608-8_16
复制
发表时间:
2014-12
期刊:
影响因子:
--
通讯作者:
C. Forler;S. Lucks;Jakob Wenzel
中科院分区:
文献类型:
--
作者:
C. Forler;S. Lucks;Jakob Wenzel
Most of the common password scramblers hinder password-guessing attacks by “key stretching”, e.g., by iterating a cryptographic hash function many times. With the increasing availability of cheap and massively parallel off-the-shelf hardware, iterating a hash function becomes less and less useful. To defend against attacks based on such hardware, one can exploit their limitations regarding to the amount of fast memory for each single core. The first password scrambler taking this into account was scrypt. In this paper we mount a cache-timing attack on scrypt by exploiting its password-dependent memory-access pattern. Furthermore, we show that it is possible to apply an efficient password filter for scrypt based on a malicious garbage collector. As a remedy, we present a novel password scrambler calledCatenawhich provides both a password-independent memory-access pattern and resistance against garbage-collector attacks. Furthermore,Catenainstantiated with the here introduced (G,λ)-DBH operation satisfies a certain time-memory tradeoff calledλ-memory-hardness, i.e., using only 1/bthe amount of memory, the time necessary to compute the password hash is increased by a factor ofbλ. Finally, we introduce a more efficient instantiation ofCatenabased on a bit-reversal graph.