Threshold Password-Hardened Encryption Services
Julian Brost, Christoph Egger, Russell W. F. Lai, Fritz Schmid, Dominique Schröder, Markus Zoppelt
摘要
Password-hardened encryption (PHE) was introduced by Lai et al. at USENIX 2018 and immediately productized by VirgilSecurity. PHE is a password-based key derivation protocol that involves an oblivious external crypto service for key derivation. The security of PHE protects against offline brute-force attacks, even when the attacker is given the entire database. Furthermore, the crypto service neither learns the derived key nor the password. PHE supports key-rotation meaning that both the server and crypto service can update their keys without involving the user. While PHE significantly strengthens data security, it introduces a single point of failure because key-derivation always requires access to the crypto service. In this work, we address this issue and simultaneously increase security by introducing threshold password-hardened encryption. Our formalization of this primitive revealed shortcomings of the original PHE definition that we also address in this work. Following the spirit of prior works, we give a simple and efficient construction using lightweight tools only. We also implement our construction and evaluate its efficiency. Our experiments confirm the practical efficiency of our scheme and show that it is more efficient than common memory-hard functions, such as scrypt. From a practical perspective this means that threshold PHE can be used as an alternative to scrypt for password protection and key-derivation, offering better security in terms of offline brute force attacks.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper4
- PASTA: PASsword-based Threshold AuthenticationShashank Agrawal, Peihan Miao, Payman Mohassel, Pratyay MukherjeeCCS 2018 · 被引用 84 次
- Phoenix: Rebirth of a Cryptographic Password-Hardening ServiceRussell W. F. Lai, Christoph Egger, Dominique Schröder, Sherman S. M. ChowUSENIX Security 2017 · 被引用 45 次
- Simple Password-Hardened Encryption ServicesRussell W. F. Lai, Christoph Egger, Manuel Reinert, Sherman S. M. Chow 等USENIX Security 2018 · 被引用 33 次
- Efficient Cryptographic Password Hardening Services from Partially Oblivious CommitmentsJonas Schneider, Nils Fleischhacker, Dominique Schröder, Michael BackesCCS 2016 · 被引用 30 次
相关 Paper
- On the Economics of Offline Password CrackingJeremiah Blocki, Benjamin Harsha, Samson ZhouS&P 2018 · 被引用 79 次
- Multi-Factor Key Derivation Function (MFKDF) for Fast, Flexible, Secure, & Practical Key ManagementVivek Nair, Dawn SongUSENIX Security 2023
- May the Force Not Be With You: Brute-Force Resistant Biometric Authentication and Key ReconstructionAlexandra Boldyreva, Deep Inder Mohan, Tianxin TangCCS 2025
- Strong Authentication without Temper-Resistant Hardware and Application to Federated IdentitiesZhenfeng Zhang, Yuchen Wang, Kang YangNDSS 2020
- Fast Homomorphic Evaluation of LWR-based PRFsAmit Deo, Marc Joye, Benoît Libert, Benjamin R. Curtis 等CCS 2025
