SESS: A Security-Enhanced Secret Storage Scheme for Password Managers

被引:0
|
作者
Hao Fang [1 ]
Hu Aiqun [1 ]
Le Shi [1 ]
Tao Li [1 ]
机构
[1] Southeast Univ, Sch Informat Sci & Engn, Nanjing, Jiangsu, Peoples R China
关键词
password; authentication; secret share;
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Password-based authentication mechanism is used widely for its simplicity. However, due to the rapidly growth of computation power nowadays, low-entropy passwords and data protected by such passwords become more and more easy to attack. For against offline dictionary attacks with memorizable passwords, one may use interactive protocols, making offline guessing impossible. Then only online guessing, of which the times can be limited, remains for the attacker. In this paper we propose such a scheme, for securely storing high-entropy keys and other secret data shared in local storage and servers in the cloud, employing only low-entropy password. Even if one of the two parties in the protocol is cracked, the security of valuable data is still guaranteed. Our scheme is merely based on the assumption that one-way function exists, and is also easy to implement.
引用
收藏
页数:5
相关论文
共 50 条
  • [1] A Security-Enhanced Federated Learning Scheme Based on Homomorphic Encryption and Secret Sharing
    Shen, Cong
    Zhang, Wei
    Zhou, Tanping
    Zhang, Lingling
    MATHEMATICS, 2024, 12 (13)
  • [2] Security analysis of a security-enhanced certificateless signature scheme
    Yang, Xiaodong
    Wang, Jinli
    Chen, Chunlin
    Li, Ting
    Wang, Meiding
    Wang, Caifen
    PROCEEDINGS OF 2019 IEEE 3RD INFORMATION TECHNOLOGY, NETWORKING, ELECTRONIC AND AUTOMATION CONTROL CONFERENCE (ITNEC 2019), 2019, : 2029 - 2033
  • [3] A Security-Enhanced Remote Platform Integrity Attestation Scheme
    Song Cheng
    Liu Bing
    Xin Yang
    Yang Yixian
    Li Zhongxian
    Yin Han
    2009 5TH INTERNATIONAL CONFERENCE ON WIRELESS COMMUNICATIONS, NETWORKING AND MOBILE COMPUTING, VOLS 1-8, 2009, : 4420 - +
  • [4] Storekeeper: A Security-Enhanced Cloud Storage Aggregation Service
    Pereira, Sancha
    Alves, Andre
    Santos, Nuno
    Chaves, Ricardo
    PROCEEDINGS OF 2016 IEEE 35TH SYMPOSIUM ON RELIABLE DISTRIBUTED SYSTEMS (SRDS), 2016, : 111 - 120
  • [5] That Was Then, This Is Now: A Security Evaluation of Password Generation, Storage, and Autofill in Browser-Based Password Managers
    Oesch, Sean
    Ruoti, Scott
    PROCEEDINGS OF THE 29TH USENIX SECURITY SYMPOSIUM, 2020, : 2165 - 2182
  • [6] Enhanced Textual Password Scheme for Better Security and Memorability
    Bhanbhro, Hina
    Hassan, Syed Raheel
    Nizamani, Shah Zaman
    Bakhsh, Sheikh Tahir
    Alassafi, Madini O.
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2018, 9 (07) : 209 - 215
  • [7] A Security-Enhanced Identity-Based Batch Provable Data Possession Scheme for Big Data Storage
    Zhao, Jining
    Xu, Chunxiang
    Chen, Kefei
    KSII TRANSACTIONS ON INTERNET AND INFORMATION SYSTEMS, 2018, 12 (09): : 4576 - 4598
  • [8] Security-Enhanced Signaling Scheme in Software Defined Optical Network
    Wang, Dongshan
    Ma, Yue
    Du, Jiang
    Ji, Yutong
    Song, Yanbin
    2018 10TH INTERNATIONAL CONFERENCE ON COMMUNICATION SOFTWARE AND NETWORKS (ICCSN), 2018, : 286 - 289
  • [9] A security-enhanced scheme for MQTT protocol based on domestic cryptographic algorithm
    Liu, Zechao
    Liang, Tao
    Lyu, Jiazhuo
    Lang, Dapeng
    COMPUTER COMMUNICATIONS, 2024, 221 : 1 - 9
  • [10] A security-enhanced scheme for MQTT protocol based on domestic cryptographic algorithm
    Liu, Zechao
    Liang, Tao
    Lyu, Jiazhuo
    Lang, Dapeng
    Computer Communications, 2024, 221 : 1 - 9