Secondary Hash Matching for Privacy-Preserving Passcode Cracking
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing hash cracking methods require users to submit their passcode hashes to a service provider in the clear, compromising security and relying on the provider's trustworthiness, and they are resource-intensive, necessitating specialized hardware.
Innovation Solution
A privacy-preserving hash cracking method where users compute a secondary hash on their hashed passcodes, submit only a defined portion of this secondary hash to a service provider, and perform the final matching locally, using a centralized wordlist to reduce resource demands and maintain security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If users submit their passcode hashes to a service provider in the clear, then the service provider can perform hash cracking, but security is compromised and users must trust the provider
Solution Approach 1:
The hash cracking process is segmented into two parts: the service provider performs preliminary cracking on hashed versions of passcodes and stores results in a database, while the user's device performs final verification by comparing the submitted hash against retrieved results. This segmentation allows the service provider to handle computational work without accessing actual passcode hashes, thereby maintaining security while enabling cracking functionality.
Solution Approach 2:
A hashed version of the passcode serves as an intermediary between the user's actual passcode and the cracking database. The service provider cracks this intermediary hash rather than the original passcode hash, and the user's device verifies the result by comparing against the submitted intermediary hash. This intermediary mechanism enables the service provider to perform cracking operations without compromising user security.
2Productivity
If specialized hardware with GPUs is used for hash cracking, then computational speed is improved, but hardware cost and complexity increase
Solution Approach 1:
The user's own device performs the final verification step by computing the hash of the candidate passcode and comparing it against the submitted hash. This self-service approach eliminates the need for specialized GPU hardware on user devices, as the computationally intensive preliminary cracking is handled by the service provider's infrastructure, while the user only needs to perform simple hash computation and comparison operations.
3Ease of operation
If a centralized wordlist is used for hash cracking, then resource demands on user devices are reduced, but network communication is required
Solution Approach 1:
The service provider performs preliminary hash cracking operations on a centralized database containing hashed versions of passcodes from a wordlist before the user submits their hash. This preliminary action allows the user's device to avoid storing or processing large wordlists locally, reducing resource demands while maintaining the ability to perform cracking through network-based verification.
Data Source
AI summary
Clear text passcodes are recovered from hashed versions of passcodes in a computational efficient and privacy preserving manner. A service provider computes an initial hash of clear text passcodes in a wordlist, computes a subsequent hash on top of the initial hash, and groups or bins the clear text passcodes based on a portion (e.g., prefix) of their subsequent hashes. A client computes a subsequent hash of a hashed passcode to be cracked, and sends a request specifying a portion of the subsequent hash to the service provider. The service provider returns a set of clear text passcodes whose hash of a hash has a match with the specified portion. The client locally computes the initial hash of clear text passcodes in the returned set, and determines if any of the resulting hashes match the hashed passcode to be cracked, and if so the passcode is considered cracked.


