Encyclopedia of Cryptography, Security and Privacy(2025)
被引用8|浏览5
摘要
A salt is a t-bit random string that may be prepended or appended to a user’s password prior to application of a one-way function in order to make dictionary attacks less effective. Both the salt and the hash (or encryption) of the augmented password are stored in the password file on the system. When the user subsequently enters a password, the system looks up the salt associated with that user, augments the password with the salt, applies the one-way function to the augmented password, and compares the result with the stored value. It is important to note that the work factor for finding a particular user’s password is unchanged by salting because the salt is stored in cleartext in the password file. However, it can substantially increase the work factor for generating random passwords and comparing them with the entire password file, since each possible password could be augmented with any possible salt. The effort required to find the password associated with an entry in the password file is multiplied by the smaller of {the number of passwords, 2t} compared with a password file containing hashes (or encryptions) of unsalted passwords. Another benefit of salting is that two users who choose the same password will have different entries in the system password file; therefore, simply reading the file will not reveal that the passwords are the same.
更多
查看译文
关键词
Genomic Signal Processing,Spiking Neural P Systems,Molecular Computation,Numerical Characterization,Genetic Algorithms