首页> 外文会议>IEEE Symposium on Security and Privacy >Cracking-Resistant Password Vaults Using Natural Language Encoders
【24h】

Cracking-Resistant Password Vaults Using Natural Language Encoders

机译:使用自然语言编码器的破解密码保险库

获取原文

摘要

Password vaults are increasingly popular applications that store multiple passwords encrypted under a single master password that the user memorizes. A password vault can greatly reduce the burden on a user of remembering passwords, but introduces a single point of failure. An attacker that obtains a user's encrypted vault can mount offline brute-force attacks and, if successful, compromise all of the passwords in the vault. In this paper, we investigate the construction of encrypted vaults that resist such offline cracking attacks and force attackers instead to mount online attacks. Our contributions are as follows. We present an attack and supporting analysis showing that a previous design for cracking-resistant vaults -- the only one of which we are aware -- actually degrades security relative to conventional password-based approaches. We then introduce a new type of secure encoding scheme that we call a natural language encoder (NLE). An NLE permits the construction of vaults which, when decrypted with the wrong master password, produce plausible-looking decoy passwords. We show how to build NLEs using existing tools from natural language processing, such as n-gram models and probabilistic context-free grammars, and evaluate their ability to generate plausible decoys. Finally, we present, implement, and evaluate a full, NLE-based cracking-resistant vault system called NoCrack.
机译:Password Vaults越来越受欢迎的应用程序,这些应用程序存储在用户记忆的单个主密码下加密的多个密码。密码保管库可以大大减少用户记忆密码的负担,但引入了单一的故障。获取用户加密Vault的攻击者可以安装脱机Brute-Force攻击,如果成功,则会危及保管库中的所有密码。在本文中,我们调查了加密保险库的构建,抵抗这种离线开裂攻击和强制攻击者,而不是安装在线攻击。我们的贡献如下。我们展示了一种攻击和支持分析,表明抗裂耐火拱顶的先前设计 - 我们所知道的唯一一个 - 实际上可以降低相对于传统的基于密码的方法的安全性。然后,我们引入了一种新型的安全编码方案,我们称之为自然语言编码器(NLE)。 NLE允许构建保险库,当用错误的主密码解密时,会产生可粘合的诱饵密码。我们展示了如何使用自然语言处理的现有工具构建NLE,例如N-GRAM模型和概率的无线语法,并评估它们产生合理诱饵的能力。最后,我们展示,实施,掌握了一种称为NOCrack的完整NLE的抗裂保险库系统。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号