Parcae: A Blockchain-Based PRF Service for Everyone

被引:0
作者
Wyss, Elizabeth [1 ]
Davidson, Drew [1 ]
机构
[1] Univ Kansas, Lawrence, KS 66045 USA
来源
DIGITAL FORENSICS AND CYBER CRIME, ICDF2C 2021 | 2022年 / 441卷
关键词
Blockchain; Smart contract; Password; PRF;
D O I
10.1007/978-3-031-06365-7_20
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Pseudorandom function (PRF) services are utilized to cryptographically harden password hashes against offline brute-force attacks. State-of-the-art implementations of PRF services can additionally offer benefits such as detection of online attacks and practical key rotation, but the cost of doing so in a publicly distributed setting is requiring clients to trust a third party service. These third party services are not incentivized to behave honestly and pose as a single point of failure for Denial of Service (DoS) attacks. A successful DoS attack mounted against a deployed PRF service would prevent its clients from authenticating their users' passwords, thus making it impossible for users to log in to those clients' services. To address these issues, we design and implement Parcae, the first blockchain-based publicly distributed PRF service. Parcae offers all of the additional benefits provided by state-of-the-art PRF services while also providing DoS attack resilience and service auditing capabilities through use of a permissioned blockchain. Performance analysis shows that our implementation of Parcae is practical and can scale to meet the needs of a dynamically growing client base in a publicly distributed setting.
引用
收藏
页码:328 / 341
页数:14
相关论文
empty
未找到相关数据