Dynamic salt generation for mobile data security using elliptic curves against precomputation attacks
by Bh. Padma; G.V.S. Raj Kumar
International Journal of Image Mining (IJIM), Vol. 2, No. 3/4, 2017

Abstract: Pattern lock is a mechanism that most of the people set to their Android smart phones. As the built-in pattern lock system adds an extra layer of protection and is one of the innovative unlock methods supported by Android, a fair quantity of study has been done about its (in)security. Pattern locks are not difficult to crack and are vulnerable to precomputation attacks such as brute forcing, dictionaries and rainbow tables. Older versions of Android produce SHA-1 signatures for authentication process which are not salted hashes. However, the newer versions of Android pattern locks utilise scrypt hash function that generates random salt value which needs to be stored in the database to withstand such attacks. But for pattern passwords attaching a salt value is still found not to be enough and susceptible to brute force. This research, therefore, proposes a method where it helps to produce and append a salt value to a password dynamically by representing the pattern using points of an elliptic curve. After the implementation and analysis, the results show this method exhibits strict avalanche criterion and passwords will become more tolerant to brute forcing, and other precomputation attacks which makes it more difficult to compromise.

Online publication date: Fri, 21-Jul-2017

The full text of this article is only available to individual subscribers or to users at subscribing institutions.

 
Existing subscribers:
Go to Inderscience Online Journals to access the Full Text of this article.

Pay per view:
If you are not a subscriber and you just want to read the full contents of this article, buy online access here.

Complimentary Subscribers, Editors or Members of the Editorial Board of the International Journal of Image Mining (IJIM):
Login with your Inderscience username and password:

    Username:        Password:         

Forgotten your password?


Want to subscribe?
A subscription gives you complete access to all articles in the current issue, as well as to all articles in the previous three years (where applicable). See our Orders page to subscribe.

If you still need assistance, please email subs@inderscience.com