Certain Number-Theoretic Questions in Access Control.
ResearchPublished 1974
Examines the use of pseudorandom numbers as passwords in databank systems that have many inquiry terminals. It shows that various logistically attractive periodic password generation and distribution systems are vulnerable to simple number-theoretic analyses that permit deducing of the passwords of all the inquiry stations. New generation and distribution strategies of the mixed congruential type to reduce such vulnerabilities are proposed and analyzed. It is shown that there is considerably more protection against cracking if the assignment order of passwords to stations is permuted each period. 24 pp. Ref.
Document Details
- Copyright: RAND Corporation
- Availability: Web Only
- Year: 1974
- Pages: 24
- Document Number: R-1494-NSF
Citation
RAND Style Manual
Chicago Manual of Style
This publication is part of the RAND report series. The report series, a product of RAND from 1948 to 1993, represented the principal publication documenting and transmitting RAND's major research findings and final research.
This document and trademark(s) contained herein are protected by law. This representation of RAND intellectual property is provided for noncommercial use only. Unauthorized posting of this publication online is prohibited; linking directly to this product page is encouraged. Permission is required from RAND to reproduce, or reuse in another form, any of its research documents for commercial purposes. For information on reprint and reuse permissions, please visit www.rand.org/pubs/permissions.
RAND is a nonprofit institution that helps improve policy and decisionmaking through research and analysis. RAND's publications do not necessarily reflect the opinions of its research clients and sponsors.