CRII: SaTC: Towards the Development of Stronger Memory-Hard Functions for Secure Password Hashing
CRII: SaTC: Towards the Development of Stronger Memory-Hard Functions for Secure Password Hashing
批准号:
1755708
负责人:
Jeremiah Blocki
金额:
$17.5万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2018
资助国家:
美国
项目状态:
已结题
起止时间:
2018-08-01 至 2020-07-31
中文摘要
点击翻译按钮获取中文摘要
英文摘要
Recent data breaches have exposed billions of user passwords to the dangerous threat of an offline password attacker who attempts to guess each user's password by brute force. Because an offline attacker can validate each password guess by itself using stolen password hashes from a data breach it is not possible to "lock out" an offline attacker after several incorrect guesses. The attacker is limited only by the computational resources necessary to mount a brute-force attack. To mitigate the risk of an offline attack the goal of a secure password hashing algorithm is to ensure that a brute force attack is prohibitively expensive even if the attacker has access to customized hardware such as an Application Specific Integrated Circuit (ASIC) that is optimized for password cracking. Memory hard functions (MHFs), functions whose computation require a large amount of memory, are a crucial cryptographic tool to achieve this goal since memory is expensive even on an ASIC. This project advances scientific understanding of memory hard functions and will directly impact future cryptographic standards for password hashing.The project is developing improved cryptanalysis techniques to evaluate the security of an MHF resulting in a deeper understanding of currently deployed MHFs. A main goal of this work is to design practical constructions of MHFs with provably optimal memory hardness in terms of bandwidth hardness, sustained space complexity, and amortized area-time complexity. Furthermore, the project focuses on establishing a scientific basis for tuning the parameters of an MHF to ensure that brute-force attacks are prohibitively expensive.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(14)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
DOI:
10.1109/sp46215.2023.10179431
发表时间:
2021-05
期刊:
2023 IEEE Symposium on Security and Privacy (SP)
影响因子:
--
作者:
[Jeremiah Blocki;Peiyuan Liu]
通讯作者:
Jeremiah Blocki;Peiyuan Liu
Locally Decodable/Correctable Codes for Insertions and Deletions
用于插入和删除的本地可解码/可纠正代码
DOI:
10.4230/lipics.fsttcs.2020.16
发表时间:
2020
期刊:
40th IARCS Annual Conference on Foundations of Software Technology and Theoretical Computer Science
影响因子:
--
作者:
[Block, A, Blocki, J, Grigorescu, E, Kulkarni, S, Zhu, M.]
通讯作者:
Zhu, M.
DOI:
10.4230/lipics.itcs.2020.36
发表时间:
2020
期刊:
Leibniz international proceedings in informatics
影响因子:
--
作者:
[Ameri, M, Blocki, J, Zhou, S.]
通讯作者:
Zhou, S.
Relaxed Locally Correctable Codes in Computationally Bounded Channels*
计算有限通道中的宽松局部可校正代码*
DOI:
10.1109/isit.2019.8849322
发表时间:
2019
期刊:
Relaxed Locally Correctable Codes in Computationally Bounded Channels
影响因子:
--
作者:
[Blocki, Jeremiah, Gandikota, Venkata, Grigorescu, Elena, Zhou, Samson]
通讯作者:
Zhou, Samson
DOI:
10.56553/popets-2022-0084
发表时间:
2022-07
期刊:
Proc. Priv. Enhancing Technol.
影响因子:
--
作者:
[Jeremiah Blocki;Wuwei Zhang]
通讯作者:
Jeremiah Blocki;Wuwei Zhang
共 14 条
CAREER: Cryptographic Tools for Usable Human Authentication
-
批准号:2047272
-
项目类别:Continuing Grant
-
资助金额:$59.19万
-
财政年份:2021
-
负责人:Jeremiah Blocki
-
依托单位:
海外基金