conference-paper

Hashing Algorithm for Protecting Credential Information Against Channel Interception and Server-Side Data Leakage

Research footprint

At a glance

Citations
2
References
9
Comments
0
Paper overview

Öz

This research proposes a novel algorithm for password hashing, called the Sandwich Hashing algorithm, designed to protect credential information from channel interception as well as server-side data leakage. The algorithm comprises three main steps: credential information enrollment, credential information hashing at the client side, and credential information checking at the server side. Sandwich Hashing employs slow but secure hash functions like bcrypt or Argon2, combined with PBKDF2, to provide robust security against rainbow-table and brute-force attacks. By using unique, random salts and timestamp buffers for each credential check, the algorithm enhances the protection of credential information from channel interception and server-side data leakage. Furthermore, hash values are partially stored on the server to resist such attacks. However, it is acknowledged that the algorithm remains vulnerable to parallel attacks involving simultaneous channel interception and server data leakage. This study details the algorithm’s implementation, parameter settings, security capabilities, and limitations, demonstrating its superiority over traditional server-side and client-side hashing methods.

Record transparency

Publication details

DOI
10.1109/icsec62781.2024.10770628
OpenAlex
W4404953053
Document type
conference-paper
Language
EN
Last metadata update
Community

Comments

Oturum Açın to join the discussion.

  1. No comments yet. Start the discussion.