课题基金 / 基金详情

Untargeted Attacks in (Password-Based) Cryptography

Untargeted Attacks in (Password-Based) Cryptography
(基于密码的)密码学中的非针对性攻击
批准号:
EP/V034065/1
负责人:
Pooya Farshim
金额:
$33.79万
依托单位:
依托单位国家:
英国
项目类别:
Research Grant
财政年份:
2022
资助国家:
英国
项目状态:
未结题
起止时间:
2022 至 --

项目摘要

项目成果

相似基金

相关文献

中文摘要
翻译
点击翻译按钮获取中文摘要
英文摘要
admin/123456; user/qwerty; root/vizxv; farshim/*********. Passwords permeate our lives: the security and privacy of many (perhaps all) of our on-line banking, commerce, and communication deeply rely on passwords. Yet they are one of the weakest links in securing systems. Storing username-passwords in plaintext, although convenient, seriously undermines security as evidenced by frequent leaks. Hashing passwords, i.e., applying a transformation that hides them, can reduce risks while still allowing for authentication. However, "123456" may well be a password chosen by someone, and then compromised. This proposal will address a current gap in our understanding of password-based cryptography in multi-instance environments where everyone is a target. We will investigate fundamental cryptographic techniques that are used to mitigate some of the risks associated in such environments. The novelty of our approach is that besides considering system-wide risks, we will consider preprocessing attacks which can speed up password-cracking by orders of magnitude. Our goal will be to show that the cryptanalytic effort needed to compromise users scales up well with the number of users targeted, and according to how "unguessable" system-wide passwords are. Formulating and studying measures of unguessability will be our starting point. These metrics will be developed with the view of usage in cryptographic contexts. For example, we will ask to what extent hashing of passwords preserves their unguessability. Crucially, we will incorporate appropriate modelling of preprocessing, so that amortised adversarial resources, such as the use of "rainbow tables," are accounted for. Alongside salting, which is a common practice to "decouple" security of users, we will consider deeper countermeasures. These include iteration, which slows down the rate of hashing, and modern memory-hard designs, which exploit uniformity of memory-access speeds across different platforms to thwart hardware-assisted attacks. In addition to unguessability, stronger notions of security that guarantee secure composition in a variety of contexts will be studied. Special attention will be paid to derive security bounds that are compatible with (real-world) parameters set according to best-known attacks. Alongside, we will also develop a solid understanding of the foundational cryptographic theory, as multi-instance security enjoys close links with amplification of hardness. The use of passwords is widespread in the security and ITC industries and their weakness is well recognised, especially in multi-user scenarios (such as IoT environments). This project will promote the creation of cryptographic standards for password hashing that are rigorously supported by security proofs. The final outcome will be an increased confidence in the resilience of our cyberspace.
期刊论文(1)
专著(0)
科研奖励(0)
会议论文
Theory of Cryptography - 20th International Conference, TCC 2022, Chicago, IL, USA, November 7-10, 2022, Proceedings, Part III
密码学理论 - 第 20 届国际会议,TCC 2022,美国伊利诺伊州芝加哥,2022 年 11 月 7-10 日,会议记录,第三部分
DOI: 10.1007/978-3-031-22368-6_8
发表时间: 2022
期刊:
影响因子: --
作者: [Bauer B]
通讯作者: Bauer B
海外基金