Preventing Cryptographic Attacks Using AI-hard Password Authentication
T V Raghavasimhan, S Manoj, J. Dhalia Sweetlin, Soumik Rakshit · 2023
Contemporary adversaries are incapable of cracking a hash function within reasonable time. However, advancements in quantum computing would empower such adversaries to perform more computations in a shorter time span, leading to a major security crisis. Integrating artificial intelligence based approaches that are hard problems such as natural language understanding or CAPTCHA can help with future-proofing security. Hence, this work proposes a CAPTCHA-like challenge that adds AI-Hardness to authenticate the client password. In the proposed system, no information about the password is directly sent in client-server communication and cannot be captured by adversaries. Server generates a challenge text and sends it to the client, which is then hashed with the client password. The output is embedded into an image and is XORed twice with the hash generated with the client password and sent to the server. This introduces randomness in the image. The server reverses the process using its copy of the password. The server retrieves the challenge text from the image and compares it with the original challenge text sent by the server to the client earlier. If the two challenge texts match, the client is authenticated. The system was evaluated based on the number of iterations required to perform a brute-force attack, correlation between the encrypted values of similar passwords and success rate of authentication. The system produced better results. As the challenge text is embedded in the image, it is difficult for bots to read. Though the challenge text is human readable, it is secured under many layers of a salted image. The size of the image and the randomness provided drastically increase the time required for an adversary to succeed in his attack.