Stay away from my passwords! Revisiting the security of honeyword-based systems
Tingting RAO , Wanying XU , Peng XU , Wei WANG , Zhaojun LU , Mauro CONTI , Kaitai LIANG
Front. Comput. Sci. ›› 2027, Vol. 21 ›› Issue (4) : 2104803
Honeywords are decoys stored alongside real passwords in credential databases. A real-world application of honeywords is the honeyword-based authentication system that detects malicious login attempts by utilizing these deceptive fake passwords. Existing honeyword-based authentication systems face two key restrictions: 1) the authentication server is a single point of full trust (i.e., it is not allowed to be intruded upon or colluded with by attackers), and 2) the stored real passwords are vulnerable to tweaking attacks once attackers gain knowledge of the passwords from other sources. To address the above challenges, we introduce SecHive, a secure three-layer honeyword-based authentication system with a hash-query server. SecHive ensures real password security even when the authentication server is semi-honest instead of fully honest. Moreover, we design a new honeyword generation method called , which is embedded in SecHive to detect tweaking attacks effectively. Our extensive experimental results prove that SecHive improves security over state-of-the-art honeyword-based authentication systems, in particular, at least a 7.39x improvement in the accuracy of detecting tweaking attacks.
privacy / password security / honeyword / authentication system / honeyword-based authentication
| [1] |
|
| [2] |
|
| [3] |
|
| [4] |
|
| [5] |
|
| [6] |
|
| [7] |
|
| [8] |
|
| [9] |
|
| [10] |
|
| [11] |
|
| [12] |
|
| [13] |
|
| [14] |
|
| [15] |
|
| [16] |
|
| [17] |
|
| [18] |
|
| [19] |
|
| [20] |
|
| [21] |
China OSA. Cybersecurity technology-Public key infrastructure-Online certificate status protocol. GB/T 19713-2025, See Openstd.samr.gov.cn/bzgk/gb/newGbInfo?hcno=96D7566804296DF20B4376DDD968D471, 2025 |
| [22] |
|
| [23] |
|
| [24] |
|
| [25] |
|
| [26] |
|
| [27] |
Amazon DynamoDB. Pricing for on-demand capacity. Amazon. See Aws.amazon.com/dynamodb/pricing/on-demand/, 2025 |
| [28] |
|
| [29] |
|
| [30] |
|
| [31] |
|
| [32] |
|
| [33] |
|
| [34] |
|
| [35] |
|
Higher Education Press
/
| 〈 |
|
〉 |