【24h】

Do you think your passwords are secure?

机译:您认为您的密码是否安全?

获取原文

摘要

Many systems rely on passwords for authentication. Due to numerous accounts for different services, users have to choose and remember a significant number of passwords. Password-Manager applications address this issue by storing the user's passwords. They are especially useful on mobile devices, because of the ubiquitous access to the account passwords. Password-Managers often use key derivation functions to convert a master password into a cryptographic key suitable for encrypting the list of passwords, thus protecting the passwords against unauthorized, off-line access. Therefore, design and implementation flaws in the key derivation function impact password security significantly. Design and implementation problems in the key derivation function can render the encryption on the password list useless, by for example allowing efficient bruteforce attacks, or - even worse - direct decryption of the stored passwords. In this paper, we analyze the key derivation functions of popular Android Password-Managers with often startling results. With this analysis, we want to raise the awareness of developers of security critical apps for security, and provide an overview about the current state of implementation security of security-critical applications.
机译:许多系统依靠验证密码。由于众多的账户不同的服务,用户必须选择并记住密码的显著数量。密码管理器应用程序通过存储用户的密码解决这一问题。他们是在移动设备上特别有用,因为无处不在的访问帐户密码。密码管理者经常使用的密钥导出函数,以主密码转换成适合用于加密的密码的列表中,从而保护密码防止未经授权的,离线访问的加密密钥。因此,设计和实施缺陷的密钥导出函数的冲击密码显著的安全性。在密钥导出函数的设计和实施方面的问题可以使口令列表没用上的加密,例如通过允许高效的暴力破解攻击,或者 - 甚至更糟 - 存储的密码直接解密。在本文中,我们分析了时下流行的Android密码管理器的密钥导出函数与常令人吃惊的结果。有了这样的分析,我们要提高的安全保障关键应用程序开发者的意识,并提供有关安全关键型应用程序实施安全现状的概述。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号