A password vault encrypts and stores a user’s multiple passwords in a vault, enabling only to remember the master password. A honey vault is a specific type of password vault that yields plausible-looking decoy vaults when the master password is incorrectly guessed. This forces attackers to shift from offline guessings to online verifications. A number of honey vault schemes have been proposed, yet most of the existing schemes have not considered the behavior of attackers in practical scenarios. Accordingly, we provide a system model and a new security metric to capture the attacker’s abilities. When a user registers, a website only allows passwords meeting specific requirements, we call this password creation policies. We reveal that the attacker can use password creation policies to distinguish honey vaults, which brings significant advantages to the attacker. Experimental results show that checking only five passwords can exclude 90% honey vaults. To resist this policy verification attack, we propose that passwords following different creation policies must be processed with different distribution-transforming encoders (DTEs), rather than one common DTE as in previous schemes. To meet this demand, we provide an algorithm that can construct ideal DTEs for any determined password distribution. We believe this work provides new feasible directions for DTE, and contributes to a better understanding of honey vault.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

How to Design Honey Vault Schemes

  • Chensheng Zhang,
  • Tingwei Fan,
  • Jingwei Jiang

摘要

A password vault encrypts and stores a user’s multiple passwords in a vault, enabling only to remember the master password. A honey vault is a specific type of password vault that yields plausible-looking decoy vaults when the master password is incorrectly guessed. This forces attackers to shift from offline guessings to online verifications. A number of honey vault schemes have been proposed, yet most of the existing schemes have not considered the behavior of attackers in practical scenarios. Accordingly, we provide a system model and a new security metric to capture the attacker’s abilities. When a user registers, a website only allows passwords meeting specific requirements, we call this password creation policies. We reveal that the attacker can use password creation policies to distinguish honey vaults, which brings significant advantages to the attacker. Experimental results show that checking only five passwords can exclude 90% honey vaults. To resist this policy verification attack, we propose that passwords following different creation policies must be processed with different distribution-transforming encoders (DTEs), rather than one common DTE as in previous schemes. To meet this demand, we provide an algorithm that can construct ideal DTEs for any determined password distribution. We believe this work provides new feasible directions for DTE, and contributes to a better understanding of honey vault.