首页> 外文会议>International Conference on String Processing and Information Retrieval >Improving Usability Through Password-Corrective Hashing
【24h】

Improving Usability Through Password-Corrective Hashing

机译:通过密码纠正散列提高可用性

获取原文

摘要

We propose a way to increase the usability of password authentication systems by compensating for transposition and substitution errors. We show how to correct for these errors with low false positive rates (i.e., low probability that an arbitrary string will be accepted as the password for authentication). Thus our techniques increase usability with provably little loss of security. In particular, we propose applying a single password-corrective hash function to each entered password attempt. The key property of the hash function is that two strings differing by a single data entry error be likely to be hashed to the same key, while more substantially differing strings are hashed to different keys. We develop precise analytical formulae for the precision/recall tradeoffs for a variety of corrective hash functions. We evaluate these methods at parameter values reflecting common classes of keys/passwords. Finally, we evaluate these schemes using a popular crack-list (dictionary) of 680,000 common words. We show that we can correct for all user transposition errors while reducing the computational cost of a crack attack by only 13%.
机译:我们提出了一种通过补偿转换和替换错误来提高密码认证系统的可用性。我们展示了如何用低误率的这些错误来纠正这些错误(即,任意字符串将被接受为身份验证的密码的低概率)。因此,我们的技术可以提高可用性,从而略微损失安全性。特别是,我们建议将单个密码校正哈希函数应用于每个输入的密码尝试。散列函数的关键属性是,通过单个数据输入误差的两个字符串可能被散列到相同的键,而散列更大不同的字符串到不同的键。我们为各种校正散列函数开发精确/召回权衡的精确分析公式。我们在反映键/密码的常用类别的参数值下评估这些方法。最后,我们使用680,000个常用词的流行裂缝列表(字典)评估这些方案。我们展示我们可以纠正所有用户转换错误,同时降低裂缝攻击的计算成本仅为13%。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号