首页> 外文会议>International Conference on Passwords >Private Password Auditing Short Paper
【24h】

Private Password Auditing Short Paper

机译:私人密码审核短文

获取原文

摘要

Password is the foremost mean to achieve data and computer security. Hence, choosing a strong password which may withstand dictionary attacks is crucial. In order to ensure that strong passwords are chosen, system administrators often rely on password auditors to filter weak password digests. Several tools aimed at preventing digest misuse have been designed to aid auditors in their task. We however show that the objective remains a far cry as these tools essentially reveal the digests corresponding to weak passwords. As a case study, we discuss the issues with Blackhash, and develop the notion of Private Password Auditing - a mechanism that does not require a system administrator to reveal password digests to an external auditor and symmetrically the dictionaries remain private to the auditor. We further present constructions based on Private Set Intersection and its variant, and evaluate a proof-of-concept implementation against real-world dictionaries.
机译:密码是实现数据和计算机安全性的最重要意义。因此,选择可能抵御字典攻击的强密码至关重要。为了确保选择强密码,系统管理员经常依赖密码审计师来过滤弱密码摘要。旨在防止摘要滥用的若干工具旨在援助审计员任务。然而,我们表明,由于这些工具基本上揭示了对应于密码弱密码的摘要,因此目标仍然是迅速的哭声。作为一个案例研究,我们讨论了Blackhash的问题,并制定了私人密码审计的概念 - 一种不需要系统管理员向外部审计员显示密码摘要的机制,并对称字典仍然私有到审核员。我们进一步基于私有设定交叉路口及其变体的构造,并评估对真实世界词典的验证实施。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号