DAHash: Distribution Aware Tuning of Password Hashing Costs

DAHash: Distribution Aware Tuning of Password Hashing Costs
复制标题

DAHash:密码散列成本的分布感知调整

DOI:
10.1007/978-3-662-64331-0_20
复制
发表时间:
2021
期刊:
International Conference on Financial Cryptography and Data Security (FC 2021
影响因子:
--
通讯作者:
Blocki, Jeremiah.
Blocki, Jeremiah.
中科院分区:
--
文献类型:
--
作者:
Bai, Wenjie;Blocki, Jeremiah.

文献摘要

参考文献

被引文献

相似文献

入侵认证服务器并窃取所有加密密码散列的攻击者能够对每个用户的密码进行离线暴力攻击。针对密码的离线暴力攻击越来越普遍,并且有据可查的人类倾向于选择低熵密码和/或在多个帐户中重复使用这些密码,从而放大了这种危险。通常部署中等难度的密码散列函数,以通过增加攻击者的猜测成本来帮助保护密码免受离线攻击。然而,由于认证服务器是资源受限的,并且必须避免引入大量的认证延迟,因此可以使密码散列函数“硬”到何种程度是有限制的。观察到不同用户选择的密码强度存在很大差距,我们引入了DAHash(分布式感知密码哈希),这是一种新的机制,可以减少攻击者将破解的密码数量。我们的关键见解是,资源受限的认证服务器可以动态调整的硬度参数的密码哈希函数的基础上(估计)的用户密码的强度。我们引入了一个Stackelberg游戏模型之间的相互作用的防御者(认证服务器)和离线攻击者。我们的模型允许防御者优化DAHash的参数,例如,指定在散列弱/中等/高强度密码时花费的工作量。我们使用几个大规模的密码频率数据集,实证评估我们的差异化成本密码哈希机制的有效性。我们发现,使用我们的机制的防御者可以减少一个理性的离线攻击者破解密码的比例。
An attacker who breaks into an authentication server and steals all of the cryptographic password hashes is able to mount an offline-brute force attack against each user’s password. Offline brute-force attacks against passwords are increasingly commonplace and the danger is amplified by the well documented human tendency to select low-entropy password and/or reuse these passwords across multiple accounts. Moderately hard password hashing functions are often deployed to help protect passwords against offline attacks by increasing the attacker’s guessing cost. However, there is a limit to how “hard” one can make the password hash function as authentication servers are resource constrained and must avoid introducing substantial authentication delay. Observing that there is a wide gap in the strength of passwords selected by different users we introduce DAHash (Distribution Aware Password Hashing) a novel mechanism which reduces the number of passwords that an attacker will crack. Our key insight is that a resource-constrained authentication server can dynamically tune the hardness parameters of a password hash function based on the (estimated) strength of the user’s password. We introduce a Stackelberg game to model the interaction between a defender (authentication server) and an offline attacker. Our model allows the defender to optimize the parameters of DAHash e.g., specify how much effort is spent in hashing weak/moderate/high strength passwords. We use several large scale password frequency datasets to empirically evaluate the effectiveness of our differentiated cost password hashing mechanism. We find that the defender who uses our mechanism can reduce the fraction of passwords that would be cracked by a rational offline attacker by up to.
密码分析攻击的全部成本
DOI: --
发表时间: 2004
影响因子: 3
作者:
M. Wiener
通讯作者: M. Wiener
比特币人才流失:检查比特币人才钱包的使用和滥用
DOI: --
发表时间: 2016
期刊: Financial Cryptography
影响因子: --
作者:
Marie Vasek;Joseph Bonneau;R. Castellucci;C. Keith;T. Moore
通讯作者: T. Moore
停止密码谜题:通过人类可记忆的密钥进行难以破解的加密
DOI: --
发表时间: 2007
期刊: USENIX Security Symposium
影响因子: --
作者:
Xavier Boyen
通讯作者: Xavier Boyen
修复混凝土裂缝:重新审视带有辅助输入的随机预言
DOI: 10.1007/978-3-319-56614-6_16
发表时间: 2017
期刊: IACR Cryptol. ePrint Arch.
影响因子: --
作者:
Y. Dodis;Siyao Guo;Jonathan Katz
通讯作者: Jonathan Katz