Multi-Factor Credential Hashing for Asymmetric Brute-Force Attack Resistance

06/13/2023
by   Vivek Nair, et al.
0

Since the introduction of bcrypt in 1999, adaptive password hashing functions, whereby brute-force resistance increases symmetrically with computational difficulty for legitimate users, have been our most powerful post-breach countermeasure against credential disclosure. Unfortunately, the relatively low tolerance of users to added latency places an upper bound on the deployment of this technique in most applications. In this paper, we present a multi-factor credential hashing function (MFCHF) that incorporates the additional entropy of multi-factor authentication into password hashes to provide asymmetric resistance to brute-force attacks. MFCHF provides full backward compatibility with existing authentication software (e.g., Google Authenticator) and hardware (e.g., YubiKeys), with support for common usability features like factor recovery. The result is a 10^6 to 10^48 times increase in the difficulty of cracking hashed credentials, with little added latency or usability impact.

READ FULL TEXT

page 9

page 15

research
12/15/2021

Cybersecurity Revisited: Honeytokens meet Google Authenticator

Although sufficient authentication mechanisms were enhanced by the use o...
research
08/10/2023

Usability Assessment of the OnlyKey Hardware Two-Factor Authentication Key Among Low Vision or Blind Users

Hardware security keys undoubtedly have advantage for users as "usabilit...
research
01/25/2021

DAHash: Distribution Aware Tuning of Password Hashing Costs

An attacker who breaks into an authentication server and steals all of t...
research
02/13/2020

Sensitivity of Wardrop Equilibria: Revisited

For single-commodity networks, the increase of the price of anarchy is b...
research
08/16/2019

MFA is a Waste of Time! Understanding Negative Connotation Towards MFA Applications via User Generated Content

Traditional single-factor authentication possesses several critical secu...
research
08/10/2022

Multi-Factor Key Derivation Function (MFKDF)

We present the first general construction of a Multi-Factor Key Derivati...
research
06/26/2023

MFDPG: Multi-Factor Authenticated Password Management With Zero Stored Secrets

While password managers are a vital tool for internet security, they can...

Please sign up or login with your details

Forgot password? Click here to reset