课题基金 / 基金详情

Bridging Theory and Practice in Password-Based Cryptography

Bridging Theory and Practice in Password-Based Cryptography
基于密码的密码学的理论与实践的桥梁
批准号:
2605368
负责人:
金额:
$0.0万
依托单位:
依托单位国家:
英国
项目类别:
Studentship
财政年份:
2021
资助国家:
英国
项目状态:
未结题
起止时间:
2021 至 --

项目摘要

项目成果

相似基金

相关文献

中文摘要
翻译
在线身份验证通常是基于密码的。虽然充分了解基于密码的加密系统的安全界限是设计健壮实例的先决条件,但仍有一些系统尚未接受先进的分析方法。像多实例安全[1]这样的分析框架允许导出与基于密码的加密相关的安全界限。这个多实例示例从更高的抽象中形式化了安全性--不是关注单个实例的安全性,而是分析整个系统。这拓宽了方法,允许分析第二道防线。来自Bellare et的示例应用程序。艾尔[1]是密码加盐的常见做法的正式安全证明。公开盐渍不会影响对手恢复单个密码的优势,但会极大地影响恢复所有密码的优势。Bellare et.艾尔正式提出了一个多实例案例的不可微概念来证明这一点。通过在对安全概念没有更全面的理解的情况下构建系统(这些框架允许我们这样做),我们冒着错过简单的安全改进(如加盐)的风险。现代攻击场景可能需要在多实例环境中对重复的、内存硬的散列进行预处理的字典。未来的场景可能会涉及基于量子的攻击,能够在(平方根)n时间内搜索n个长度的列表[2]。未来验证基于密码的密码系统将涉及到考虑这些情况的结合。目的本项目的目的是在基于密码的密码学背景下的可证明安全性理论与基于密码的新协议在野外使用的实例之间架起桥梁。这意味着三个目标,可以线性接近:-对基于密码的密码学的当前格局进行研究。这意味着调查现实生活中密码的生成和分布,以便根据经验结果建立模型。使用正式的安全分析评估模型的界限。-考虑内存硬、经过预处理的场景-为多实例情况构建严格的安全界限。-将界限推向在量子攻击者案件中保持舒适的水平,其中试图维护安全的各方是非量子的。
英文摘要
Online authentication is most often password-based. While a full understanding of the security bounds on password-based encryption systems is a precondition for designing robust instances, there exist systems which have yet to be subjected to advanced methods of analysis. Analytical frameworks like multi-instance security [1] allow for deriving security bounds relevant to password-based encryption. This multi-instance example formalises the security from a higher abstraction - instead of focusing of the security of a single instance, the system as a whole in analysed. This broadens the approach, allowing for analysis of second lines of defence. The example application from Bellare et. al. [1] is a formal security proof for the common practice of password salting. Public salting doesn't impact the adversary's advantage for recovering a single password, but greatly effects the advantage for recovering them all. Bellare et. al. formalised a conception of indifferentiability for a multi-instance case to prove this. By building systems without the fuller understanding of security conceptions, which these frameworks allow us, we run the risk of missing simple security improvements (like salting). A modern attack scenario could entail preprocessed dictionaries of iterated, memory-hard hashes in a multi-instance environment. Future scenarios could feasibly involve quantum based attacks, with the capability of searching n length lists in (square root) n time [2]. Future proofing password-based cryptographic systems will involve considering the union of these situations. Aims The aims of this project are intended to bridge the theory of provable security for the context of password based cryptography, with the instances of new password-based protocols used in the wild. This means three goals, to be approached linearly: -Conduct research into the current landscape of password-based cryptography. Which means investigating the generation and distribution of passwords in real life, in order to produce a model based on empirical results. Assess bounds for the model with formal security analysis. - Consider the memory-hard, preprocessed scenario - constructing a tight security bound for the multi-instance case. -Push bounds to levels which remain comfortable in the quantum attacker case, where the parties attempting to maintain security are non-quantum.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
国内基金
海外基金
Research on Quantum Field Theory without a Lagrangian Description
  • 批准号:
    24ZR1403900
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2024
  • 负责人:
    SATOSHI NAWATA
  • 依托单位:
基于isomorph theory研究尘埃等离子体物理量的微观动力学机制
  • 批准号:
    12247163
  • 项目类别:
    专项项目
  • 资助金额:
    18.00万元
  • 批准年份:
    2022
  • 负责人:
    黄栋
  • 依托单位:
Toward a general theory of intermittent aeolian and fluvial nonsuspended sediment transport
  • 批准号:
    --
  • 项目类别:
    --
  • 资助金额:
    55万元
  • 批准年份:
    2022
  • 负责人:
    Thomas Pahtz
  • 依托单位:
英文专著《FRACTIONAL INTEGRALS AND DERIVATIVES: Theory and Applications》的翻译
  • 批准号:
    12126512
  • 项目类别:
    数学天元基金项目
  • 资助金额:
    12.0万元
  • 批准年份:
    2021
  • 负责人:
    李常品
  • 依托单位: