On the Depth-Robustness and Cumulative Pebbling Cost of Argon2i

On the Depth-Robustness and Cumulative Pebbling Cost of Argon2i
复制标题

关于 Argon2i 的深度鲁棒性和累积卵石成本

DOI:
10.1007/978-3-319-70500-2_15
复制
发表时间:
2017
期刊:
Theory of Cryptography. TCC 2017
影响因子:
--
通讯作者:
Zhou, S.
Zhou, S.
中科院分区:
--
文献类型:
--
作者:
Blocki, J.;Zhou, S.

文献摘要

参考文献

被引文献

相似文献

Argon 2 i是一个独立于数据的存储器硬函数,赢得了密码哈希比赛。密码散列算法已经被集成到几个开源加密库中,如libsodium。在本文中,我们分析了计算Argon 2 i的累积内存成本。在积极的一面,我们提供了Argon 2 i的下限。在消极的一面,我们展示了对Argon 2 i的改进攻击,这表明我们的下限几乎是紧的。特别地,我们证明了(1)Argon 2 i DAG是-可约的。(2)Argon 2 i的累计卵石成本最多为。这改进了[AB 17]的前一个最佳上界。(3)Argon 2 i DAG具有深度鲁棒性。相比之下,[ABP 17 a]的分析仅确定Argon 2 i具有深度稳健性。(4)Argon 2 i的累积pebbling复杂度至少为。这改进了[ABP 17 a]之前的最佳界,并表明Argon 2 i具有比竞争方案(如Catena或Balloon Hashing)更高的累积内存开销。我们还表明Argon 2 i具有高分数深度鲁棒性,这强烈表明Argon 2的数据依赖模式能够抵抗时空权衡攻击。
Argon2i is a data-independent memory hard function that won the password hashing competition. The password hashing algorithm has already been incorporated into several open source crypto libraries such as libsodium. In this paper we analyze the cumulative memory cost of computing Argon2i. On the positive side we provide a lower bound for Argon2i. On the negative side we exhibit an improved attack against Argon2i which demonstrates that our lower bound is nearly tight. In particular, we show that(1)An Argon2i DAG is-reducible.(2)The cumulative pebbling cost for Argon2i is at most. This improves upon the previous best upper bound of[AB17].(3)Argon2i DAG is-depth robust. By contrast, analysis of [ABP17a] only established that Argon2i was-depth robust.(4)The cumulative pebbling complexity of Argon2i is at least. This improves on the previous best bound of[ABP17a] and demonstrates that Argon2i has higher cumulative memory cost than competing proposals such as Catena or Balloon Hashing.We also show that Argon2i has highfractionaldepth-robustness which strongly suggests that data-dependent modes of Argon2 are resistant to space-time tradeoff attacks.
关于交替 II
DOI: 10.1007/bf00286494
发表时间: 1980
期刊: Acta Informatica
影响因子: 0.6
作者:
W. Paul;R. Reischuk
通讯作者: R. Reischuk
Lyra:基于密码的密钥派生,内存和处理成本可调
DOI: 10.1007/s13389-013-0063-5
发表时间: 2014
影响因子: 1.9
作者:
Leonardo C. Almeida;Ewerton R. Andrade;Paulo L. Barreto;M. Simplício
通讯作者: M. Simplício
关于深度减少和格栅
DOI: 10.1109/sfcs.1983.38
发表时间: 1983
期刊: 24th Annual Symposium on Foundations of Computer Science (sfcs 1983)
影响因子: --
作者:
G. Schnitger
通讯作者: G. Schnitger
黑白卵石的累积空间和分辨率
DOI: 10.4230/lipics.itcs.2017.38
发表时间: 2017
期刊: IACR Cryptol. ePrint Arch.
影响因子: --
作者:
J. Alwen;Susanna F. de Rezende;Jakob Nordström;Marc Vinyals
通讯作者: Marc Vinyals
一系列具有昂贵深度缩减的图
DOI: 10.1016/0304-3975(82)90113-x
发表时间: 1981
期刊: Theor. Comput. Sci.
影响因子: --
作者:
G. Schnitger
通讯作者: G. Schnitger