Stronger Password-Based Encryption Using I/O Hardness

BSidesLV 2015

Presented by: Greg Zaverucha
Date: Wednesday August 05, 2015
Time: 14:00 - 14:25
Location: Tuscany
Track: Passwords

Password-based encryption needs all the help it can get to withstand brute-force attacks. We repurpose an old idea to encrypt data so that each password guess requires processing all of the encrypted data. Then, we'll look at some use cases to see how the costs change for the attacker and defender. In a brute force attack, this can mean a large increase in attacker I/O, with little cost increase to defenders, who must process all of the data anyway.

Greg Zaverucha

Greg is a software engineer in the MSR Security and Cryptography group at Microsoft. He performs research in applied cryptography, implements cryptographic primitives, and helps product teams use cryptography securely. Prior to joining Microsoft, Greg worked on applied research, standardization and product security at Certicom/Blackberry. Greg holds a PhD in CS specializing in cryptography from the University of Waterloo.


KhanFu - Mobile schedules for INFOSEC conferences.
Mobile interface | Alternate Formats