Dynamic salt generation for mobile data security using elliptic curves against precomputation attacks

Bh. Padma, G. R. Kumar
{"title":"Dynamic salt generation for mobile data security using elliptic curves against precomputation attacks","authors":"Bh. Padma, G. R. Kumar","doi":"10.1504/IJIM.2017.10006243","DOIUrl":null,"url":null,"abstract":"Pattern lock is a mechanism that most of the people set to their Android smart phones. As the built-in pattern lock system adds an extra layer of protection and is one of the innovative unlock methods supported by Android, a fair quantity of study has been done about its (in)security. Pattern locks are not difficult to crack and are vulnerable to precomputation attacks such as brute forcing, dictionaries and rainbow tables. Older versions of Android produce SHA-1 signatures for authentication process which are not salted hashes. However, the newer versions of Android pattern locks utilise scrypt hash function that generates random salt value which needs to be stored in the database to withstand such attacks. But for pattern passwords attaching a salt value is still found not to be enough and susceptible to brute force. This research, therefore, proposes a method where it helps to produce and append a salt value to a password dynamically by representing the pattern using points of an elliptic curve. After the implementation and analysis, the results show this method exhibits strict avalanche criterion and passwords will become more tolerant to brute forcing, and other precomputation attacks which makes it more difficult to compromise.","PeriodicalId":433219,"journal":{"name":"The International Journal on the Image","volume":"18 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2017-07-25","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"4","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"The International Journal on the Image","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1504/IJIM.2017.10006243","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 4

Abstract

Pattern lock is a mechanism that most of the people set to their Android smart phones. As the built-in pattern lock system adds an extra layer of protection and is one of the innovative unlock methods supported by Android, a fair quantity of study has been done about its (in)security. Pattern locks are not difficult to crack and are vulnerable to precomputation attacks such as brute forcing, dictionaries and rainbow tables. Older versions of Android produce SHA-1 signatures for authentication process which are not salted hashes. However, the newer versions of Android pattern locks utilise scrypt hash function that generates random salt value which needs to be stored in the database to withstand such attacks. But for pattern passwords attaching a salt value is still found not to be enough and susceptible to brute force. This research, therefore, proposes a method where it helps to produce and append a salt value to a password dynamically by representing the pattern using points of an elliptic curve. After the implementation and analysis, the results show this method exhibits strict avalanche criterion and passwords will become more tolerant to brute forcing, and other precomputation attacks which makes it more difficult to compromise.
针对预计算攻击的椭圆曲线移动数据安全动态盐生成
模式锁定是大多数人在安卓智能手机上设置的一种机制。由于内置模式锁系统增加了一层额外的保护,并且是Android支持的创新解锁方式之一,因此对其安全性进行了大量研究。模式锁不难破解,而且容易受到暴力破解、字典和彩虹表等预计算攻击的攻击。旧版本的Android为身份验证过程生成SHA-1签名,这不是盐哈希。然而,新版本的Android模式锁使用scrypt哈希函数生成随机盐值,需要存储在数据库中以抵御此类攻击。但是对于模式密码,附加盐值仍然是不够的,并且容易被暴力破解。因此,本研究提出了一种方法,该方法通过使用椭圆曲线的点表示模式来动态地生成和附加密码的盐值。经过实现和分析,结果表明,该方法具有严格的雪崩准则,密码对暴力破解和其他预计算攻击的容忍度更高,使其更难以被攻破。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信