Halting Password Puzzles: Hard-to-break Encryption from Human-memorable Keys

Halting Password Puzzles: Hard-to-break Encryption from Human-memorable Keys
复制标题

停止密码谜题:通过人类可记忆的密钥进行难以破解的加密

DOI:
--
复制
发表时间:
2007
期刊:
USENIX Security Symposium
影响因子:
--
通讯作者:
Xavier Boyen
Xavier Boyen
中科院分区:
--
文献类型:
--
作者:
Xavier Boyen

文献摘要

被引文献

相似文献

我们重新审视“纯密码”为基础的密钥推导和加密的古老问题,并暴露出安全漏洞,在当前的实现,源于密钥推导函数(KDF)的结构缺陷。我们提倡一个新的重新设计,命名为停止KDF(HKDF),我们彻底激励这些理由:1。通过让密码所有者选择哈希迭代计数,我们获得了操作的灵活性,并消除了许多现有方案所面临的快速过时。2.通过在猜测迭代计数的工作中抛出停止问题扳手,我们将与任何攻击者的安全差距扩大到其理论最优值。3.通过并行化密钥推导,我们让合法用户利用他们所能聚集的所有计算能力,这反过来又进一步提高了攻击者的门槛。 HKDF是实用和通用的:它们可以使用任何密码,任何硬件,以及对用户界面的微小更改。作为演示,我们提供了TrueCrypt和GnuPG包的真实实现,并具体讨论了它们的安全优势。
We revisit the venerable question of "pure password"- based key derivation and encryption, and expose security weaknesses in current implementations that stem from structural flaws in Key Derivation Functions (KDF). We advocate a fresh redesign, named Halting KDF (HKDF), which we thoroughly motivate on these grounds: 1. By letting password owners choose the hash iteration count, we gain operational flexibility and eliminate the rapid obsolescence faced by many existing schemes. 2. By throwing a Halting-Problem wrench in the works of guessing that iteration count, we widen the security gap with any attacker to its theoretical optimum. 3. By parallelizing the key derivation, we let legitimate users exploit all the computational power they can muster, which in turn further raises the bar for attackers. HKDFs are practical and universal: they work with any password, any hardware, and a minor change to the user interface. As a demonstration, we offer real-world implementations for the TrueCrypt and GnuPG packages, and discuss their security benefits in concrete terms.