首页> 外文期刊>International Journal of Embedded Systems >Phoney: protecting password hashes with threshold cryptology and honeywords
【24h】

Phoney: protecting password hashes with threshold cryptology and honeywords

机译:Phoney:使用阈值密码和蜜词保护密码哈希

获取原文
获取原文并翻译 | 示例
           

摘要

Password file disclosure has attracted a lot of attention recently. Once password files are stolen, attackers can quickly crack large numbers of passwords. In this paper, we propose Phoney, a system which employs a threshold cryptosystem to encrypt the password hashes in the password file and honeywords to confuse attackers. With the help of Phoney, attackers cannot get any password information easily even they steal the password files. All the password hashes are encrypted by our threshold cryptosystem. Even they are able to compromise the cryptosystem, attackers cannot identify the real password easily because of the false passwords (honeywords) deliberately added for each account to confuse the adversaries. In addition, attempts of submitting a honeyword will cause alarms to be set off. Experiments show that the time and storage cost of Phoney are acceptable, but the cracking search space is increased significantly.
机译:密码文件泄露最近引起了很多关注。一旦密码文件被盗,攻击者可以迅速破解大量密码。在本文中,我们提出了Phoney系统,该系统采用阈值密码系统对密码文件中的密码散列进行加密,并使用蜜字使攻击者感到困惑。在Phoney的帮助下,攻击者即使窃取密码文件也无法轻松获得任何密码信息。所有密码哈希均由我们的阈值密码系统加密。即使他们能够破坏密码系统,攻击者也无法轻易识别真实密码,因为故意为每个帐户添加了错误密码(蜜语),以使对手感到困惑。此外,尝试提交蜜语将导致警报被取消。实验表明,Phoney的时间和存储成本是可以接受的,但破解搜索空间却大大增加了。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号