We gratefully acknowledge support from
the Simons Foundation and member institutions.
Full-text links:

Download:

Current browse context:

cs.CR

Change to browse by:

cs

References & Citations

DBLP - CS Bibliography

Bookmark

(what is this?)
CiteULike logo BibSonomy logo Mendeley logo del.icio.us logo Digg logo Reddit logo

Computer Science > Cryptography and Security

Title: One Password: An Encryption Scheme for Hiding Users' Register Information

Authors: Bo Zhao, Yu Zhou
Abstract: In recent years, the attack which leverages register information (e.g. accounts and passwords) leaked from 3rd party applications to try other applications is popular and serious. We call this attack "database collision". Traditionally, people have to keep dozens of accounts and passwords for different applications to prevent this attack. In this paper, we propose a novel encryption scheme for hiding users' register information and preventing this attack. Specifically, we first hash the register information using existing safe hash function. Then the hash string is hidden, instead a coefficient vector is stored for verification. Coefficient vectors of the same register information are generated randomly for different applications. Hence, the original information is hardly cracked by dictionary based attack or database collision in practice. Using our encryption scheme, each user only needs to keep one password for dozens of applications.
Comments: The method has not been tested in practice
Subjects: Cryptography and Security (cs.CR)
Cite as: arXiv:1710.04353 [cs.CR]
  (or arXiv:1710.04353v2 [cs.CR] for this version)

Submission history

From: Bo Zhao [view email]
[v1] Thu, 12 Oct 2017 03:27:56 GMT (435kb,D)
[v2] Fri, 24 Jun 2022 03:32:23 GMT (0kb,I)

Link back to: arXiv, form interface, contact.