Simple Password-Hardened Encryption Services
Russell W. F. Lai, Christoph Egger, Manuel Reinert, Sherman S. M. Chow, Matteo Maffei, Dominique Schröder
摘要
Passwords and access control remain the popular choice for protecting sensitive data stored online, despite their well-known vulnerability to brute-force attacks. A natural solution is to use encryption. Although standard practices of using encryption somewhat alleviate the problem, decryption is often needed for utility, and keeping the decryption key within reach is obviously dangerous.
To address this seemingly unavoidable problem in data security, we propose password-hardened encryption (PHE). With the help of an external crypto server, a service provider can recover the user data encrypted by PHE only when an end user supplied a correct password. PHE inherits the security features of passwordhardening (Usenix Security '15), adding protection for the user data. In particular, the crypto server does not learn any information about any user data. More importantly, both the crypto server and the service provider can rotate their secret keys, a proactive security mechanism mandated by the Payment Card Industry Data Security Standard (PCI DSS).
We build an extremely simple password-hardened encryption scheme. Compared with the state-of-the-art password-hardening scheme (Usenix Security '17), our scheme only uses minimal number-theoretic operations and is, therefore, 30% -50% more efficient. In fact, our extensive experimental evaluation demonstrates that our scheme can handle more than 525 encryption and (successful) decryption requests per second per core, which shows that it is lightweight and readily deployable in large-scale systems. Regarding security, our scheme also achieves a stronger soundness property, which puts less trust on the good behavior of the crypto server.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper6
- Updatable Oblivious Key Management for Storage SystemsStanislaw Jarecki, Hugo Krawczyk, Jason K. ReschCCS 2019 · 被引用 52 次
- How to Attack and Generate HoneywordsDing Wang, Yunkai Zou, Qiying Dong, Yuanming Song 等S&P 2022 · 被引用 45 次
- Threshold Password-Hardened Encryption ServicesJulian Brost, Christoph Egger, Russell W. F. Lai, Fritz Schmid 等CCS 2020 · 被引用 24 次
- Incrementally Updateable Honey Password VaultsHaibo Cheng, Wenting Li, Ping Wang, Chao-Hsien Chu 等USENIX Security 2021 · 被引用 15 次
- Probability Model Transforming Encoders Against Encoding AttacksHaibo Cheng, Zhixiong Zheng, Wenting Li, Ping Wang 等USENIX Security 2019 · 被引用 12 次
它引用的顶会 Paper2
- Phoenix: Rebirth of a Cryptographic Password-Hardening ServiceRussell W. F. Lai, Christoph Egger, Dominique Schröder, Sherman S. M. ChowUSENIX Security 2017 · 被引用 45 次
- Efficient Cryptographic Password Hardening Services from Partially Oblivious CommitmentsJonas Schneider, Nils Fleischhacker, Dominique Schröder, Michael BackesCCS 2016 · 被引用 30 次
相关 Paper
- Password-Protected Key Retrieval with(out) HSM ProtectionSebastian H. Faller, Tobias Handirk, Julia Hesse, Máté Horváth 等CCS 2024 · 被引用 3 次
- Equi-Joins over Encrypted Data for Series of QueriesMasoumeh Shafieinejad, Suraj Gupta, Jin Yang Liu, Koray Karabina 等ICDE 2022 · 被引用 14 次
- CHORUS: Secret Recovery with Ephemeral Client CommitteesDeevashwer Rathee, Emma Dauterman, Allison Li, Raluca Ada PopaS&P 2026 · 被引用 1 次
- Efficient Confidentiality-Preserving Data Analytics over Symmetrically Encrypted DatasetsSavvas Savvides, Darshika Khandelwal, Patrick EugsterVLDB 2020 · 被引用 38 次
- Egalitarian ComputingAlex Biryukov, Dmitry KhovratovichUSENIX Security 2016 · 被引用 26 次
