• •    

蜜罐加密技术在私密数据的应用

银伟1,邢国强2,周红建1   

  1. 1. 95899部队
    2. 中国人民解放军95899部队
  • 收稿日期:2017-05-16 修回日期:2017-07-31 发布日期:2017-07-31
  • 通讯作者: 银伟

Honey Encryption Applications in Private Data

  • Received:2017-05-16 Revised:2017-07-31 Online:2017-07-31
  • Contact: Wei YIN

摘要: 暴力破解时,攻击者能根据破解结果判断所猜测密码的正确性,因此给足充裕的时间,暴力破解总能找到正确密码并成功退出。蜜罐加密技术使得在即使猜错口令时也能输出看似正确的消息,使得攻击者无法判断破解是否成功,让攻击者不知道何时该终止暴力破解。实现蜜罐加密技术,并将其应用到身份证号码、手机号码和银行卡密码,保护数据存储安全。对蜜罐加密技术进行评估并提出增强型机制解决性能问题。在实现过程中,考虑均衡分布和随机分布的消息空间,并将蜜罐加密技术运用到对称加密算法和公钥加密机制。最后总结了在蜜罐加密技术设计、实现和评估过程中学习到的经验。

关键词: 蜜罐加密, 隐私, 安全, 蜜罐, 加密

Abstract: In brute-force attacks, the decode output can confirm whether the guessed key is correct or not. Therefore given enough time, the brute-force attack can exit with the correct key determined. Honey encryption makes the output look like that the message is correctly decrypted even if the guessed key is incorrect. In this way the attacker cannot determine whether the brute-force attack is successful and when to quit the brute-force process. In this paper, the honey encryption mechanism is designed and implemented. It is also applied to three types of private data including Chinese identification numbers, mobile phone numbers and debit card passwords. The performance of our mechanism is evaluated and an enhancement is proposed to address the overhead issue. In the implementation, uniformly/non-uniformly distributed message space and symmetric/ asymmetric encryption mechanisms are covered. Lessons learned from designing, implementing and evaluating the honey encryption mechanism are also presented.

Key words: honey encryption, privacy, security, honey, encryption

中图分类号: