Decoy Password Vaults: At Least as Hard as Steganography?

Decoy Password Vaults: At Least as Hard as Steganography?
复制标题

诱骗密码库:至少和隐写术一样难?

DOI:
10.1007/978-3-319-58469-0_24
复制
发表时间:
2017
期刊:
影响因子:
--
通讯作者:
R. Böhme
R. Böhme
中科院分区:
--
文献类型:
--
作者:
C. Pasquini;P. Schöttle;R. Böhme

文献摘要

参考文献

被引文献

相似文献

最近提出了防破解密码库,其目的是阻止离线攻击。这需要生成在统计上与真实密码无法区分的合成密码库。在这项工作中,我们在这个问题和隐写术之间建立了概念联系,其中隐写对象必须在覆盖对象中不可检测。我们比较这两个框架并强调相似之处和差异。此外,我们将隐写术文献中获得的结果转移到诱饵生成的背景中。我们的结果包括完全安全的诱饵金库的不可行性,以及安全诱饵金库至少与安全隐写术一样难以构建的猜想。
Cracking-resistant password vaults have been recently proposed with the goal of thwarting offline attacks. This requires the generation of synthetic password vaults that are statistically indistinguishable from real ones. In this work, we establish a conceptual link between this problem and steganography, where the stego objects must be undetectable among cover objects. We compare the two frameworks and highlight parallels and differences. Moreover, we transfer results obtained in the steganography literature into the context of decoy generation. Our results include the infeasibility of perfectly secure decoy vaults and the conjecture that secure decoy vaults are at least as hard to construct as secure steganography.
DOI: --
发表时间: 2017
期刊: Request for Comments
影响因子: --
作者:
K. Moriarty;B. Kaliski;Andreas Rusch
通讯作者: Andreas Rusch