SPHINX: A Password Store that Perfectly Hides Passwords from Itself

SPHINX: A Password Store that Perfectly Hides Passwords from Itself
复制标题

SPHINX:完美隐藏密码的密码存储

DOI:
--
复制
发表时间:
2017
期刊:
IEEE International Conference on Distributed Computing Systems
影响因子:
--
通讯作者:
Nitesh Saxena
Nitesh Saxena
中科院分区:
--
文献类型:
--
作者:
Maliheh Shirvanian;Stanislaw Jarecki;H. Krawczyk;Nitesh Saxena

文献摘要

被引文献

相似文献

密码管理器(又名商店或保险库)允许用户通过与“设备”进行交互,以为其多个受密码保护的服务存储和检索密码(例如,智能手机或在线智能手机或在线)第三方服务)基于单个令人难忘的(低渗透率)主密码。假设使用高注册密码,现有密码管理器在Web服务妥协时均可击败离线词典攻击。但是,由于需要存储在主密码中的密码和/或需要将主密码输入到设备(如智能手机管理人员)中,因此它们很容易泄漏所有密码的泄漏,因为该设备被妥协了,因为需要存储主密码加密的密码。 。有证据表明,密码管理人员可能是有吸引力的攻击目标。在本文中,我们介绍了一种新颖的密码管理方法,即Sphinx,即使密码管理器本身已被妥协,该方法仍然安全。在Sphinx中,存储在设备上的信息在理论上独立于用户的主密码 - 攻击者闯入设备的信息不会学习有关主密码或用户特定网站特定密码的信息。此外,即使在用户与之交互时,具有完全控制设备的攻击者也没有了解主密码 - 密码未以明文形式或任何其他可能泄漏信息的方式输入设备。与现有经理不同,狮身人面像会生成严格的高渗透密码,并强制使用Web服务注册这些随机密码,从而完全击败了对服务妥协的离线词典攻击。狮身人面像的设计和安全是基于Jarecki等人的设备增强的Pake模型。这为这种构建提供了理论基础,并得到了严格的加密证明的支持。尽管Sphinx适用于不同的设备和在线平台,但在本文中,我们报告了其在智能手机上的具体实例化,因为它们作为密码管理器(甚至是两因素身份验证)的知名度和可信度。我们介绍了狮身人面像的设计,实现和性能评估,提供原型浏览器插件,智能手机应用程序和透明的设备 - 客户通信。根据我们的检查分析,狮身人面像的总体用户体验对当前经理有所改善。我们还报告了一项基于实验室的狮身人行主义性研究,这表明用户对狮身人面像的安全性和可用性的看法是高而令人满意的,与常规的基于密码的身份验证相比。最后,我们讨论如何将狮身人面像扩展到在线服务,以备份或作为独立密码管理器。
Password managers (aka stores or vaults) allow a user to store and retrieve (usually high-entropy) passwords for her multiple password-protected services by interacting with a "device" serving the role of the manager (e.g., a smartphone or an online third-party service) on the basis of a single memorable (low-entropy) master password. Existing password managers work well to defeat offline dictionary attacks upon web service compromise, assuming the use of high-entropy passwords is enforced. However, they are vulnerable to leakage of all passwords in the event the device is compromised, due to the need to store the passwords encrypted under the master password and/or the need to input the master password to the device (as in smartphone managers). Evidence exists that password managers can be attractive attack targets. In this paper, we introduce a novel approach to password management, called SPHINX, which remains secure even when the password manager itself has been compromised. In SPHINX, the information stored on the device is information theoretically independent of the user's master password - an attacker breaking into the device learns no information about the master password or the user's site-specific passwords. Moreover, an attacker with full control of the device, even at the time the user interacts with it, learns nothing about the master password - the password is not entered into the device in plaintext form or in any other way that may leak information on it. Unlike existing managers, SPHINX produces strictly high-entropy passwords and makes it compulsory for the users to register these randomized passwords with the web services, hence fully defeating offline dictionary attack upon service compromise. The design and security of SPHINX is based on the device-enhanced PAKE model of Jarecki et al. that provides the theoretical basis for this construction and is backed by rigorous cryptographic proofs of security. While SPHINX is suitable for different device and online platforms, in this paper, we report on its concrete instantiation on smartphones given their popularity and trustworthiness as password managers (or even two-factor authentication). We present the design, implementation and performance evaluation of SPHINX, offering prototype browser plugins, smartphone apps and transparent device-client communication. Based on our inspection analysis, the overall user experience of SPHINX improves upon current managers. We also report on a lab-based usability study of SPHINX, which indicates that users' perception of SPHINX security and usability is high and satisfactory when compared to regular password-based authentication. Finally, we discuss how SPHINX may be extended to an online service for the purpose of back-up or as an independent password manager.