首页> 外文会议>International Conference on Financial Cryptography and Data Security >'Give Me Letters 2, 3 and 6!': Partial Password Implementations and Attacks
【24h】

'Give Me Letters 2, 3 and 6!': Partial Password Implementations and Attacks

机译:“给我第2,3和6号!”:部分密码实现和攻击

获取原文

摘要

A partial password is a query of a subset of characters from a full password, posed as a challenge such as "Give me letters 2, 3 and 6 from your password". Partial passwords are commonly used in the consumer financial sector, both online and in telephone banking. They provide a cheap way of providing a varying challenge that prevents eavesdroppers or intermediate systems learning a shared secret in a single step. Yet, despite widespread adoption among millions of consumers, this mechanism has had little attention in the academic literature. Answers to obvious questions are not clear, for example, how many observations are needed for an attacker to learn the complete password, or to successfully answer the next challenge? In this paper we survey a number of online banking implementations of partial passwords, and investigate the security of the mechanism. In particular, we look at guessing attacks with a projection dictionary ranked by likelihood, and recording attacks which use previous information collected by an attacker. The combination of these techniques yields the best attack on partial passwords.
机译:部分密码是从完整密码的一个字符子集的查询,作为挑战,例如“给我密码中的字母2,3和6”。部分密码通常用于消费者金融部门,在线和电话银行。它们提供了一种廉价的方式,提供了一个不同的挑战,这可以防止窃听者或中间系统在一步中学习共享秘密。然而,尽管数百万消费者之间存在广泛的采用,但这种机制在学术文献中几乎没有关注。例如,明显问题的答案尚不清楚,攻击者需要多少观察员来学习完整密码,或者成功回答下一个挑战?在本文中,我们调查了一些部分密码的网上银行实施,并调查了机制的安全性。特别是,我们研究猜测攻击字典的攻击攻击,该探测字典排序,并且记录使用由攻击者收集的先前信息的攻击。这些技术的组合产生了对部分密码的最佳攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号