Suppr超能文献

作为熵博弈的密码安全

Password Security as a Game of Entropies.

作者信息

Rass Stefan, König Sandra

机构信息

System Security Group, Institute of Applied Informatics, Universität Klagenfurt, 9020 Klagenfurt, Austria.

Austrian Institute of Technology, Center for Digital Safety & Security, 1210 Vienna, Austria.

出版信息

Entropy (Basel). 2018 Apr 25;20(5):312. doi: 10.3390/e20050312.

Abstract

We consider a formal model of password security, in which two actors engage in a competition of optimal password choice against potential attacks. The proposed model is a multi-objective two-person game. Player 1 seeks an optimal password choice policy, optimizing matters of memorability of the password (measured by Shannon entropy), opposed to the difficulty for player 2 of guessing it (measured by min-entropy), and the cognitive efforts of player 1 tied to changing the password (measured by relative entropy, i.e., Kullback-Leibler divergence). The model and contribution are thus twofold: (i) it applies multi-objective game theory to the password security problem; and (ii) it introduces different concepts of entropy to measure the quality of a password choice process under different angles (and not a given password itself, since this cannot be quality-assessed in terms of entropy). We illustrate our approach with an example from everyday life, namely we analyze the password choices of employees.

摘要

我们考虑一种密码安全的形式化模型,其中两个参与者针对潜在攻击进行最优密码选择的竞争。所提出的模型是一个多目标两人博弈。参与者1寻求一种最优密码选择策略,优化密码的可记忆性(由香农熵衡量),同时对抗参与者2猜测密码的难度(由最小熵衡量),以及参与者1与更改密码相关的认知努力(由相对熵,即库尔贝克 - 莱布勒散度衡量)。因此,该模型和贡献有两个方面:(i)它将多目标博弈论应用于密码安全问题;(ii)它引入不同的熵概念,从不同角度衡量密码选择过程的质量(而不是给定密码本身,因为密码本身无法根据熵进行质量评估)。我们用一个日常生活中的例子来说明我们的方法,即分析员工的密码选择。

相似文献

1
Password Security as a Game of Entropies.作为熵博弈的密码安全
Entropy (Basel). 2018 Apr 25;20(5):312. doi: 10.3390/e20050312.
7
A Systematic Review on Password Guessing Tasks.关于密码猜测任务的系统综述。
Entropy (Basel). 2023 Sep 7;25(9):1303. doi: 10.3390/e25091303.
10
A Password Meter without Password Exposure.无密码泄露的密码强度计量器。
Sensors (Basel). 2021 Jan 6;21(2):345. doi: 10.3390/s21020345.

引用本文的文献

1
Information Theory in Game Theory.博弈论中的信息论
Entropy (Basel). 2018 Oct 24;20(11):817. doi: 10.3390/e20110817.

本文引用的文献

1
Defending Against Advanced Persistent Threats Using Game-Theory.运用博弈论抵御高级持续性威胁
PLoS One. 2017 Jan 3;12(1):e0168675. doi: 10.1371/journal.pone.0168675. eCollection 2017.

文献AI研究员

20分钟写一篇综述,助力文献阅读效率提升50倍。

立即体验

用中文搜PubMed

大模型驱动的PubMed中文搜索引擎

马上搜索

文档翻译

学术文献翻译模型,支持多种主流文档格式。

立即体验