CAREER: Cryptographic Tools for Usable Human Authentication
CAREER: Cryptographic Tools for Usable Human Authentication
批准号:
2047272
负责人:
Jeremiah Blocki
金额:
$59.19万
依托单位:
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2021
资助国家:
美国
项目状态:
未结题
起止时间:
2021-05-15 至 2026-04-30
中文摘要
点击翻译按钮获取中文摘要
英文摘要
Password authentication is a common source of frustration for users and a constant source of security vulnerabilities. Users struggle with the burdensome task of creating and remembering passwords for multiple different accounts and frequently cope by selecting weak (low-entropy) passwords and reusing the same password across multiple accounts. Over the past decade data breaches at many prominent organizations have exposed billions of these low-entropy passwords to the dangerous threat of offline brute-force attacks. Despite their shortcomings passwords continue to be the most widely adopted form of authentication. The goal of the project is to develop cryptographic tools to improve the security and usability of human authentication, especially password authentication. The project investigates new combinatorial techniques to design and analyze memory hard functions, a cryptographic primitive which can be used to protect low-entropy secrets such as passwords and biometrics against brute-force attacks. The project develops stronger memory hard functions and analyzes the concrete security of prior memory hard functions such as SCRYPT, Argon2 and DRSample. The project adapts tools from statistics and game theory to better understand the distribution over user chosen passwords and predict how password attackers will behave. The investigators study how password defenses can be tuned based on this distribution to optimally protect user accounts against attackers. Finally, the project develops mechanisms to help users (gradually) memorize stronger passwords and to help users securely manage multiple passwords without requiring users to memorize independent passwords for every account.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(14)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
The Parallel Reversible Pebbling Game: Analyzing the Post-quantum Security of iMHFs
并行可逆卵石游戏:分析 iMHF 的后量子安全性
DOI:
--
发表时间:
2022
期刊:
Theory of Cryptography Conference (TCC 2022
影响因子:
--
作者:
[Blocki, Jeremiah, Holman, Blake, Lee, Seunghoon]
通讯作者:
Lee, Seunghoon
DOI:
10.1109/sp46215.2023.10179431
发表时间:
2021-05
期刊:
2023 IEEE Symposium on Security and Privacy (SP)
影响因子:
--
作者:
[Jeremiah Blocki;Peiyuan Liu]
通讯作者:
Jeremiah Blocki;Peiyuan Liu
DOI:
10.56553/popets-2022-0084
发表时间:
2022-07
期刊:
Proc. Priv. Enhancing Technol.
影响因子:
--
作者:
[Jeremiah Blocki;Wuwei Zhang]
通讯作者:
Jeremiah Blocki;Wuwei Zhang
Cost-Asymmetric Memory Hard Password Hashing
成本不对称内存硬密码哈希
DOI:
--
发表时间:
2022
期刊:
Security and Cryptography for Networks. SCN 2022
影响因子:
--
作者:
[Bai, Wenjie, Blocki, J, Ameri, Mohammad Hassan]
通讯作者:
Ameri, Mohammad Hassan
Leibniz International Proceedings in Informatics (LIPIcs):38th Computational Complexity Conference (CCC 2023)
莱布尼茨国际信息学会议录 (LIPIcs):第 38 届计算复杂性会议 (CCC 2023)
DOI:
10.4230/lipics.ccc.2023.14
发表时间:
2023
期刊:
38th Computational Complexity Conference (CCC 2023
影响因子:
--
作者:
[Block, Alexander R., Blocki, Jeremiah, Cheng, Kuan, Grigorescu, Elena, Li, Xin, Zheng, Yu, Zhu, Minshen]
通讯作者:
Zhu, Minshen
共 14 条
CRII: SaTC: Towards the Development of Stronger Memory-Hard Functions for Secure Password Hashing
-
批准号:1755708
-
项目类别:Standard Grant
-
资助金额:$17.5万
-
财政年份:2018
-
负责人:Jeremiah Blocki
-
依托单位:
海外基金