The Experts below are selected from a list of 591 Experts worldwide ranked by ideXlab platform
Mauro Bisson - One of the best experts on this subject based on the ideXlab platform.
-
A fast, GPU based, dictionary attack to OpenPGP secret keyrings
Journal of Systems and Software, 2011Co-Authors: Fabrizio Milo, Massimo Bernaschi, Mauro BissonAbstract:We describe the implementation, based on the Compute Unified Device Architecture (CUDA) for Graphics Processing Units (GPU), of a novel and very effective approach to quickly test Passphrases used to protect private keyrings of OpenPGP cryptosystems. Our combination of algorithm and implementation, reduces the time required to test a set of possible Passphrases by three-orders of magnitude with respect to an attack based on the procedure described in the OpenPGP standard and implemented by software packages like GnuPG, and a tenfold speed up if compared to our highly tuned CPU implementation. Our solution can be considered a replacement and an extension of pgpcrack, a utility used in the past for attacking PGP. The optimizations described can be applied to other cryptosystems and confirm that the GPU architecture is also very effective for running applications that make extensive (if not exclusive) use of integer operations.
-
An Architecture for Distributed Dictionary Attacks to Cryptosystems
Journal of Computers, 2009Co-Authors: Massimo Bernaschi, Mauro Bisson, Emanuele Gabrielli, Simone TacconiAbstract:We describe a distributed computing platform to carry out large scale dictionary attacks against cryptosystems compliant to the OpenPGP standard. Moreover, we describe a simplified mechanism to quickly test Passphrases that might protect a specified private key ring. Only Passphrases that pass this test complete the (much more time consuming) full validation procedure. This approach greatly reduces the time required to test a set of possible Passphrases.
Romain Giot - One of the best experts on this subject based on the ideXlab platform.
-
Authentification faiblement contrainte par dynamique de frappe au clavier
2010Co-Authors: Romain Giot, Mohamad El-abed, Christophe RosenbergerAbstract:In this communication, we propose an authentification method based on the use of a Passphrase associated to keystroke dynamics. The main mechanisms of the system are the use of few data to create users' model (5 cap- tures), the use of an incremental learning and SVM. Experi- mentals results on a benchmark containing 100 individuals show the benefit of this new system.
-
Keystroke dynamics with low constraints SVM based Passphrase enrollment
IEEE 3rd International Conference on Biometrics: Theory Applications and Systems BTAS 2009, 2009Co-Authors: Romain Giot, Mourad Abed, Christina RosenbergerAbstract:Keystroke dynamics biometric systems have been studied for more than twenty years. They are very well perceived by users, they may be one of the cheapest biometric system (as no specific material is required) even if they are not commonly spread and used. We propose in this paper a new method based on SVM learning satisfying operational conditions (no more than 5 captures for the enrollment step). In the proposed method, users are authenticated thanks to keystroke dynamics of a Passphrase (that can be chosen by the system administrator). We use the GREYC keystroke benchmark that is composed of a large number of users (100) for validation purposes. We tested the proposed method face to four other methods from the state of the art. Experimental results show that the proposed method outperforms them in an operational context.
Bissonmauro - One of the best experts on this subject based on the ideXlab platform.
-
A fast, GPU based, dictionary attack to OpenPGP secret keyrings
Journal of Systems and Software, 2011Co-Authors: Milofabrizio, Bernaschimassimo, BissonmauroAbstract:We describe the implementation, based on the Compute Unified Device Architecture (CUDA) for Graphics Processing Units (GPU), of a novel and very effective approach to quickly test Passphrases used ...
Fabrizio Milo - One of the best experts on this subject based on the ideXlab platform.
-
A fast, GPU based, dictionary attack to OpenPGP secret keyrings
Journal of Systems and Software, 2011Co-Authors: Fabrizio Milo, Massimo Bernaschi, Mauro BissonAbstract:We describe the implementation, based on the Compute Unified Device Architecture (CUDA) for Graphics Processing Units (GPU), of a novel and very effective approach to quickly test Passphrases used to protect private keyrings of OpenPGP cryptosystems. Our combination of algorithm and implementation, reduces the time required to test a set of possible Passphrases by three-orders of magnitude with respect to an attack based on the procedure described in the OpenPGP standard and implemented by software packages like GnuPG, and a tenfold speed up if compared to our highly tuned CPU implementation. Our solution can be considered a replacement and an extension of pgpcrack, a utility used in the past for attacking PGP. The optimizations described can be applied to other cryptosystems and confirm that the GPU architecture is also very effective for running applications that make extensive (if not exclusive) use of integer operations.
Bruce Schneier - One of the best experts on this subject based on the ideXlab platform.
-
Protecting secret keys with personal entropy
Future Generation Computer Systems, 2000Co-Authors: Carl Ellison, Randy Milbert, Chris Hall, Bruce SchneierAbstract:Conventional encryption technology often requires users to protect a secret key by selecting a password or Passphrase. While a good Passphrase will only be known to the user, it also has the flaw that it must be remembered exactly in order to recover the secret key. As time passes, the ability to remember the Passphrase fades and the user may eventually lose access to the secret key. We propose a scheme whereby a user can protect a secret key using the `personal entropy' in his own life, by encrypting the Passphrase using the answers to several personal questions. We designed the scheme so the user can forget answers to a subset of the questions and still recover the secret key, while an attacker must learn the answer to a large subset of the questions in order to recover the secret key.