Can "Something You Know" Be Saved?
نویسندگان
چکیده
“Something you know,” in the form of passwords, has been the cornerstone of authentication for some time; however the inability to survive replay attack threatens this state of affairs. While “something you know” may always be used in addition to “something you have” we examine whether it can be salvaged as the solo factor for authentication. A recent surge of interest in Challenge Response authentication schemes raises the question whether a secret shared between the user and the server can allow secure access even in the presence of spyware. Our conclusion is negative. Assuming only a limit on the amount that a user can remember and calculate we find that any scheme likely to be usable is too easily brute forced if the attacker observes several logins. This is true irrespective of the details of the scheme. The vital parameter is the number of bits of the secret involved in each bit of the response. When this number is too low the scheme is easily brute-forced, but making it high makes the scheme unworkable for the user. Our conclusion is that single factor “something you know” schemes have a fundamental weakness unless the number of logins the attacker observes can be restricted.
منابع مشابه
Presenting a Hybrid Approach based on Two-stage Data Envelopment Analysis to Evaluating Organization Productivity
Measuring the performance of a production system has been an important task in management for purposes of control, planning, etc. Lord Kelvin said :“When you can measure what you are speaking about, and express it in numbers, you know something about it; but when you cannot measure it, when you cannot express it in numbers, your knowledge is of a meager and unsatisfactory kind.” Hence, manag...
متن کاملHow to Reverse Engineer an EES Device
Clearly, something in the system has to be secret. The goal of EES is that government agencies will be able to tap telephone calls, but no-one else will. To achieve this, the government must have, or know, something that no-one else does. This something is the Unit Key (KU), a cryptographic key which is different for every telephone. The basic idea is that if you know a phone’s unit key you can...
متن کاملP25: Talent and Perseverance
Many people think that all you need to succeed at anything is talent but talent alone without perseverance and determination, cannot help you achieve success. Talent is helpful but perseverance ensured one achieves success. A child can show an exceptional talent for storytelling, but if he ignores his teacher’s comments and doesn’t work on his stories, he will never be a great novel...
متن کاملHard cash boosts child health in South Africa.
sciencemag.org SCIENCE work. “The policemen don’t police, the teachers don’t teach, and the doctors don’t doctor,” he says. “We know for sure that varies orders of magnitude across countries of the world.” How then can you assume that a successful intervention in South Africa will translate to Colombia? The drive to use “easily measured indicators” to claim success and impress donors also worri...
متن کاملYou can take it with you.
One day, you will discover a new adventure and knowledge by spending more money. But when? Do you think that you need to obtain those all requirements when having much money? Why don't you try to get something simple at first? That's something that will lead you to know more about the world, adventure, some places, history, entertainment, and more? It is your own time to continue reading habit....
متن کامل