The Experts below are selected from a list of 198 Experts worldwide ranked by ideXlab platform

Shunbin Li - One of the best experts on this subject based on the ideXlab platform.

  • Energy-Efficient RAR3 Password Recovery with Dual-Granularity Data Path Strategy
    2019 IEEE International Symposium on Circuits and Systems (ISCAS), 2019
    Co-Authors: Qingyuan Ding, Zhendong Zhang, Shunbin Li
    Abstract:

    Password recovery tools are used to recover lost Passwords and regain access to precious data. Due to the extremely large time and energy consumption of Password recovery, efficient hardware accelerators are demanded to accelerate the recovery process. However, simple and regular data interconnect paths between data sources and non-blocking hash pipelines are hard to construct for Roshal ARchive version 3 (RAR3) algorithm based on field programmable gate array (FPGA) devices. The difficulty comes from the fact that the message format of the hash pipeline inputs vary with the Password Length and the secure hash algorithm 1 (SHA-1) iteration phase. To attack this problem, a dual-granularity data path adjustment strategy is proposed to eliminate the randomness of message block formats caused by the irregularity of Password Length and to efficiently schedule the data through the regular data interconnect paths. Experimental results show that the proposed hardware accelerator for RAR3 Password recovery is 3.3 × more energy-efficient than a state-of-the-art implementation Hashcat on NVIDIA GTX 1060 GPU.

  • ISCAS - Energy-Efficient RAR3 Password Recovery with Dual-Granularity Data Path Strategy
    2019 IEEE International Symposium on Circuits and Systems (ISCAS), 2019
    Co-Authors: Qingyuan Ding, Zhendong Zhang, Shunbin Li
    Abstract:

    Password recovery tools are used to recover lost Passwords and regain access to precious data. Due to the extremely large time and energy consumption of Password recovery, efficient hardware accelerators are demanded to accelerate the recovery process. However, simple and regular data interconnect paths between data sources and non-blocking hash pipelines are hard to construct for Roshal ARchive version 3 (RAR3) algorithm based on field programmable gate array (FPGA) devices. The difficulty comes from the fact that the message format of the hash pipeline inputs vary with the Password Length and the secure hash algorithm 1 (SHA-1) iteration phase. To attack this problem, a dual-granularity data path adjustment strategy is proposed to eliminate the randomness of message block formats caused by the irregularity of Password Length and to efficiently schedule the data through the regular data interconnect paths. Experimental results show that the proposed hardware accelerator for RAR3 Password recovery is 3.3 × more energy-efficient than a state-of-the-art implementation Hashcat on NVIDIA GTX 1060 GPU.

Ken R. Duffy - One of the best experts on this subject based on the ideXlab platform.

  • Guesswork, Large Deviations, and Shannon Entropy
    IEEE Transactions on Information Theory, 2013
    Co-Authors: Mark M. Christiansen, Ken R. Duffy
    Abstract:

    How hard is it to guess a Password? Massey showed that a simple function of the Shannon entropy of the distribution from which the Password is selected is a lower bound on the expected number of guesses, but one which is not tight in general. In a series of subsequent papers under ever less restrictive stochastic assumptions, an asymptotic relationship as Password Length grows between scaled moments of the guesswork and specific Renyi entropy was identified. Here, we show that, when appropriately scaled, as the Password Length grows, the logarithm of the guesswork satisfies a large deviation principle (LDP), providing direct estimates of the guesswork distribution when Passwords are long. The rate function governing the LDP possesses a specific, restrictive form that encapsulates underlying structure in the nature of guesswork. Returning to Massey's original observation, a corollary to the LDP shows that expectation of the logarithm of the guesswork is the specific Shannon entropy of the Password selection process.

  • Guesswork, Large Deviations, and Shannon Entropy
    IEEE Transactions on Information Theory, 2013
    Co-Authors: Mark M. Christiansen, Ken R. Duffy
    Abstract:

    How hard is it to guess a Password? Massey showed that a simple function of the Shannon entropy of the distribution from which the Password is selected is a lower bound on the expected number of guesses, but one which is not tight in general. In a series of subsequent papers under ever less restrictive stochastic assumptions, an asymptotic relationship as Password Length grows between scaled moments of the guesswork and specific Rényi entropy was identified. Here, we show that, when appropriately scaled, as the Password Length grows, the logarithm of the guesswork satisfies a large deviation principle (LDP), providing direct estimates of the guesswork distribution when Passwords are long. The rate function governing the LDP possesses a specific, restrictive form that encapsulates underlying structure in the nature of guesswork. Returning to Massey's original observation, a corollary to the LDP shows that expectation of the logarithm of the guesswork is the specific Shannon entropy of the Password selection process.

Qingyuan Ding - One of the best experts on this subject based on the ideXlab platform.

  • Energy-Efficient RAR3 Password Recovery with Dual-Granularity Data Path Strategy
    2019 IEEE International Symposium on Circuits and Systems (ISCAS), 2019
    Co-Authors: Qingyuan Ding, Zhendong Zhang, Shunbin Li
    Abstract:

    Password recovery tools are used to recover lost Passwords and regain access to precious data. Due to the extremely large time and energy consumption of Password recovery, efficient hardware accelerators are demanded to accelerate the recovery process. However, simple and regular data interconnect paths between data sources and non-blocking hash pipelines are hard to construct for Roshal ARchive version 3 (RAR3) algorithm based on field programmable gate array (FPGA) devices. The difficulty comes from the fact that the message format of the hash pipeline inputs vary with the Password Length and the secure hash algorithm 1 (SHA-1) iteration phase. To attack this problem, a dual-granularity data path adjustment strategy is proposed to eliminate the randomness of message block formats caused by the irregularity of Password Length and to efficiently schedule the data through the regular data interconnect paths. Experimental results show that the proposed hardware accelerator for RAR3 Password recovery is 3.3 × more energy-efficient than a state-of-the-art implementation Hashcat on NVIDIA GTX 1060 GPU.

  • ISCAS - Energy-Efficient RAR3 Password Recovery with Dual-Granularity Data Path Strategy
    2019 IEEE International Symposium on Circuits and Systems (ISCAS), 2019
    Co-Authors: Qingyuan Ding, Zhendong Zhang, Shunbin Li
    Abstract:

    Password recovery tools are used to recover lost Passwords and regain access to precious data. Due to the extremely large time and energy consumption of Password recovery, efficient hardware accelerators are demanded to accelerate the recovery process. However, simple and regular data interconnect paths between data sources and non-blocking hash pipelines are hard to construct for Roshal ARchive version 3 (RAR3) algorithm based on field programmable gate array (FPGA) devices. The difficulty comes from the fact that the message format of the hash pipeline inputs vary with the Password Length and the secure hash algorithm 1 (SHA-1) iteration phase. To attack this problem, a dual-granularity data path adjustment strategy is proposed to eliminate the randomness of message block formats caused by the irregularity of Password Length and to efficiently schedule the data through the regular data interconnect paths. Experimental results show that the proposed hardware accelerator for RAR3 Password recovery is 3.3 × more energy-efficient than a state-of-the-art implementation Hashcat on NVIDIA GTX 1060 GPU.

P. C. Van Oorschot - One of the best experts on this subject based on the ideXlab platform.

  • ACSAC - Towards secure design choices for implementing graphical Passwords
    20th Annual Computer Security Applications Conference, 2004
    Co-Authors: Julie Thorpe, P. C. Van Oorschot
    Abstract:

    We study the impact of selected parameters on the size of the Password space for "Draw-A-Secret" (DAS) graphical Passwords. We examine the role of and relationships between the number of composite strokes, grid dimensions, and Password Length in the DAS Password space. We show that a very significant proportion of the DAS Password space depends on the assumption that users will choose long Passwords with many composite strokes. If users choose Passwords having 4 or fewer strokes, with Passwords of Length 12 or less on a 5 /spl times/ 5 grid, instead of up to the maximum 12 possible strokes, the size of the DAS Password space is reduced from 58 to 40 bits. Additionally, we found a similar reduction when users choose no strokes of Length 1. To strengthen security, we propose a technique and describe a representative system that may gain up to 16 more bits of security with an expected negligible increase in input time. Our results can be directly applied to determine secure design choices, graphical Password parameter guidelines, and in deciding which parameters deserve focus in graphical Password user studies.

  • Towards secure design choices for implementing graphical Passwords
    20th Annual Computer Security Applications Conference, 2004
    Co-Authors: Julie Thorpe, P. C. Van Oorschot
    Abstract:

    We study the impact of selected parameters on the size of the Password space for "Draw-A-Secret" (DAS) graphical Passwords. We examine the role of and relationships between the number of composite strokes, grid dimensions, and Password Length in the DAS Password space. We show that a very significant proportion of the DAS Password space depends on the assumption that users will choose long Passwords with many composite strokes. If users choose Passwords having 4 or fewer strokes, with Passwords of Length 12 or less on a 5 /spl times/ 5 grid, instead of up to the maximum 12 possible strokes, the size of the DAS Password space is reduced from 58 to 40 bits. Additionally, we found a similar reduction when users choose no strokes of Length 1. To strengthen security, we propose a technique and describe a representative system that may gain up to 16 more bits of security with an expected negligible increase in input time. Our results can be directly applied to determine secure design choices, graphical Password parameter guidelines, and in deciding which parameters deserve focus in graphical Password user studies.

Mark M. Christiansen - One of the best experts on this subject based on the ideXlab platform.

  • Guesswork, Large Deviations, and Shannon Entropy
    IEEE Transactions on Information Theory, 2013
    Co-Authors: Mark M. Christiansen, Ken R. Duffy
    Abstract:

    How hard is it to guess a Password? Massey showed that a simple function of the Shannon entropy of the distribution from which the Password is selected is a lower bound on the expected number of guesses, but one which is not tight in general. In a series of subsequent papers under ever less restrictive stochastic assumptions, an asymptotic relationship as Password Length grows between scaled moments of the guesswork and specific Renyi entropy was identified. Here, we show that, when appropriately scaled, as the Password Length grows, the logarithm of the guesswork satisfies a large deviation principle (LDP), providing direct estimates of the guesswork distribution when Passwords are long. The rate function governing the LDP possesses a specific, restrictive form that encapsulates underlying structure in the nature of guesswork. Returning to Massey's original observation, a corollary to the LDP shows that expectation of the logarithm of the guesswork is the specific Shannon entropy of the Password selection process.

  • Guesswork, Large Deviations, and Shannon Entropy
    IEEE Transactions on Information Theory, 2013
    Co-Authors: Mark M. Christiansen, Ken R. Duffy
    Abstract:

    How hard is it to guess a Password? Massey showed that a simple function of the Shannon entropy of the distribution from which the Password is selected is a lower bound on the expected number of guesses, but one which is not tight in general. In a series of subsequent papers under ever less restrictive stochastic assumptions, an asymptotic relationship as Password Length grows between scaled moments of the guesswork and specific Rényi entropy was identified. Here, we show that, when appropriately scaled, as the Password Length grows, the logarithm of the guesswork satisfies a large deviation principle (LDP), providing direct estimates of the guesswork distribution when Passwords are long. The rate function governing the LDP possesses a specific, restrictive form that encapsulates underlying structure in the nature of guesswork. Returning to Massey's original observation, a corollary to the LDP shows that expectation of the logarithm of the guesswork is the specific Shannon entropy of the Password selection process.