TY - GEN
T1 - Design and analysis of password-based key derivation functions
AU - Yao, Frances F.
AU - Yin, Yiqun Lisa
N1 - Publication details (e.g. title, author(s), publication statuses and dates) are captured on an “AS IS” and “AS AVAILABLE” basis at the time of record harvesting from the data source. Suggestions for further amendments or supplementary information can be sent to [email protected].
PY - 2005
Y1 - 2005
N2 - A password-based key derivation function (KDF) - a function that derives cryptographic keys from a password - is necessary in many security applications. Like any password-based schemes, such KDFs are subject to key search attacks (often called dictionary attacks). Salt and iteration count are used in practice to significantly increase the workload of such attacks. These techniques have also been specified in widely adopted industry standards such as PKCS and IETF. Despite the importance and wide-spread usage, there has been no formal security analysis on existing constructions. In this paper, we propose a general security framework for password-based KDFs and introduce two security definitions each capturing a different attacking scenario. We study the most commonly used construction H(c)(p||s) and prove that the iteration count c, when fixed, does have an effect of stretching the password p by log2 c bits. We then analyze the two standardized KDFs in PKCS#5. We show that both are secure if the adversary cannot influence the parameters but subject to attacks otherwise. Finally, we propose a new password-based KDF that is provably secure even when the adversary has full control of the parameters. © Springer-Verlag Berlin Heidelberg 2005.
AB - A password-based key derivation function (KDF) - a function that derives cryptographic keys from a password - is necessary in many security applications. Like any password-based schemes, such KDFs are subject to key search attacks (often called dictionary attacks). Salt and iteration count are used in practice to significantly increase the workload of such attacks. These techniques have also been specified in widely adopted industry standards such as PKCS and IETF. Despite the importance and wide-spread usage, there has been no formal security analysis on existing constructions. In this paper, we propose a general security framework for password-based KDFs and introduce two security definitions each capturing a different attacking scenario. We study the most commonly used construction H(c)(p||s) and prove that the iteration count c, when fixed, does have an effect of stretching the password p by log2 c bits. We then analyze the two standardized KDFs in PKCS#5. We show that both are secure if the adversary cannot influence the parameters but subject to attacks otherwise. Finally, we propose a new password-based KDF that is provably secure even when the adversary has full control of the parameters. © Springer-Verlag Berlin Heidelberg 2005.
UR - https://www.scopus.com/pages/publications/24144446919
UR - https://www.scopus.com/record/pubmetrics.uri?eid=2-s2.0-24144446919&origin=recordpage
U2 - 10.1007/978-3-540-30574-3_17
DO - 10.1007/978-3-540-30574-3_17
M3 - RGC 32 - Refereed conference paper (with host publication)
SN - 3540243992
VL - 3376
T3 - Lecture Notes in Computer Science
SP - 245
EP - 261
BT - Topics in Cryptology - CT-RSA 2005 - The Cryptographers' Track at the RSA Conference 2005
PB - Springer Verlag
T2 - Cryptographers’ Track at the RSA Conference, CT-RSA 2005
Y2 - 14 February 2005 through 18 February 2005
ER -