How to Design Secure Honey Vault Schemes
Zhenduo Hou, Tingwei Fan, Fei Duan, Ding Wang
Abstract
Password vaults enable a user to store multiple passwords with a single master password.Honey encryption (HE) protected password vaults (called honey vaults), are promising in resisting offline master password guessing attacks.Trial-decrypted with incorrect master passwords, honey vaults are designed to yield plausible-looking decoy vaults to confuse attackers, forcing them to perform online verifications to know whether a decrypted vault is the real one.In this paper, we demonstrate how to design secure honey vault schemes in a principled approach.We first identify three major types of vulnerabilities, and propose three critical design criteria based on rigorous theories, with each aiming to address one type of vulnerability.These criteria are: (1) Employing an accurate password probability model (PPM) in the natural language encoder (NLE, a key component of a honey vault) to resist distribution-aware distinguishing attacks; (2) Employing sequence-based PPMs for unique passwords, and sufficiently concise reuse models to resist encoding attacks (USENIX SEC'19); (3) Hiding a user's real-vault-related (i.e., adaptive) PPM to resist extraction attacks (USENIX SEC'21).To meet these key criteria, we propose VaultGuard with an innovative NLE and HE-Adaptive to honey-encrypt a user's real vault and the adaptive PPM, respectively.Our NLE eliminates the first and second vulnerabilities, while HE-Adaptive addresses the third.Security evaluations on real-world data reveal that our VaultGuard can significantly enhance honey vault security, forcing attackers to perform 1.103.98times online verifications.We also provide an efficient proof-of-concept VaultGuard implementation on the client side.We believe this work provides general principles and actionable guidelines for designing secure honey vault schemes. CCS Concepts Security and privacy Authentication.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 01070563-be44-4b54-bff5-e36ae2077b2fRelated papers
- On the Security of Cracking-Resistant Password VaultsMaximilian Golla, Benedict Beuscher, Markus DürmuthCCS 2016 · 54 citations
- A Security Analysis of Honey VaultsFei Duan, Ding Wang, Chunfu JiaS&P 2024 · 3 citations
- Practically Secure Honey Password Vaults: New Design and New Evaluation against Online GuessingHaibo Cheng, Fugeng Huang, Jiahong Yang, Wenting Li et al.USENIX Security 2025
- Incrementally Updateable Honey Password VaultsHaibo Cheng, Wenting Li, Ping Wang, Chao-Hsien Chu et al.USENIX Security 2021 · 15 citations
- Probability Model Transforming Encoders Against Encoding AttacksHaibo Cheng, Zhixiong Zheng, Wenting Li, Ping Wang et al.USENIX Security 2019 · 12 citations
