首页    期刊浏览 2024年09月15日 星期日
登录注册

文章基本信息

  • 标题:On the Security Analysis of PBKDF2 in OpenOffice
  • 其他标题:On the Security Analysis of PBKDF2 in OpenOffice
  • 本地全文:下载
  • 作者:Xiaochao Li ; Cuicui Zhao ; Kun Pan
  • 期刊名称:Journal of Software
  • 印刷版ISSN:1796-217X
  • 出版年度:2015
  • 卷号:10
  • 期号:2
  • 页码:116-126
  • DOI:10.17706/jsw.10.2.116-126
  • 出版社:Academy Publisher
  • 摘要:Password-based KDF2 (PBKDF2) is widely used in file authentication mechanism and file encryption which could produce a derived key more than 160 bits long. In this paper, the security of PBKDF2 algorithm and its implementation in OpenOffice are analyzed in two modes: CSP-secure mode (Chosen Single Parameter) and CMP-secure mode (Chosen Multiple Parameters). The theoretical security of PBKDF2 is proved in CSP-secure mode by using Game-Playing technology to quantify the upper bound of adversary’s advantage. However, a security flaw is explored in CMP-secure mode. This paper presents three proposals to address the security flaw. With the theoretical derivation, the actual safety of the OpenOffice encrypted file has been discussed under the latest developments for GPU-accelerated key recovery attack capability.
  • 其他关键词:Key derivation functions, provable security, PBKDF2, adversary’s advantage
国家哲学社会科学文献中心版权所有