login

Protecting secret keys with personal entropy

Future Generation Computer SystemsPublished 1 February 2000
Carl Ellison, Chris Hall, Randy Milbert, Bruce Schneier
Citations105
SJR quartileQ1
SJR score1.55
SNIP2.23

TL;DR

A scheme whereby a user can protect a secret key using the "personal entropy" in his own life, by encrypting the passphrase using the answers to several personal questions, while an attacker must learn the answer to a large subset of the questions in order to recover the secret key.

Abstract

Conventional encryption technology often requires users to protect a secret key by selecting a password or passphrase. While a good passphrase will only be known to the user, it also has the flaw that it must be remembered exactly in order to recover the secret key. As time passes, the ability to remember the passphrase fades and the user may eventually lose access to the secret key. We propose a scheme whereby a user can protect a secret key using the "personal entropy" in his own life, by encrypting the passphrase using the answers to several personal questions. We designed the scheme so the user can forget answers to a subset of the questions and still recover the secret key, while an attacker must learn the answer to a large subset of the questions in order to recover the secret key.

Keywords

Computer ScienceBiochemistry, Genetics and Molecular Biology