http://www.ntu.edu.sg/home/rxlu/slide/20131102chenli.pdf
这个是利用LPN的难解性构建的一个系统,需要很好的随机数发生器。
2015年1月15日星期四
2014年6月24日星期二
PUF reading
2014-06-24
From [1], soft-decision is better than hard-decision, requiring nearly half the repetition bits for error correction with FRR 10^(-7). Generate 128-bit key with 3900 SRAM cells, only a single measurement. If multiple Maes et al only needs 1536.
[1] Vincent van der Leest, Bart Preneel etc, "Soft Decision Error Correction for Compact Memory-based PUFs using Single Enrollment", 2012 CHES
From [1], soft-decision is better than hard-decision, requiring nearly half the repetition bits for error correction with FRR 10^(-7). Generate 128-bit key with 3900 SRAM cells, only a single measurement. If multiple Maes et al only needs 1536.
[1] Vincent van der Leest, Bart Preneel etc, "Soft Decision Error Correction for Compact Memory-based PUFs using Single Enrollment", 2012 CHES
2014年6月4日星期三
RSA notes
1, Does RSA work for any message M?
Yes.
Even if message m and modulus n is not co-prime, ist gcd{m, n} !=1
2,
Common modulus attack on RSA when the 2 public exponents differ by a single bit
3, Common n attack
Multiple parties cannot share the same n. Because for one person, knowing {e1, d1} = knowing Phi{n} = can factor n = can find another d2 according to e2 = know plain text sent to person2
2014年5月24日星期六
random number test
1, if the File system is NTFS, /assess maybe not executable. So copy all the file to ubuntu File system.
make it.
2, segment error.
下载解压包SP800-20 sts-2.1 ,重新安装。
3, how to use
./assess 100000
make it.
2, segment error.
下载解压包SP800-20 sts-2.1 ,重新安装。
3, how to use
./assess 100000
2014年5月19日星期一
Memory scrambling
Ref: https://edipermadi.wordpress.com/tag/memory/
Memory scrambling is the process of messing up the contents of memory, either by remapping the adress, data encipherment or even both of them. The aim is to complicate data retrieval from memory, this is also useful to protect a small and sensitive stuff such as firmware.
The address remapping itself is nothing new, its actually a bijective mapping of plain address to scrambled address. In real life this keyed scrambling is made through the usage of block cipher. The mode could be enciphering or deciphering, since address scrambling is a one way mapping.
The content encipherment is working in the same way as address scrambling. It is also based on block cipher. However, content encipherment is sensitive to address and direction since the process must be able to recover the data stored at memory. The writing processis encipherment while the reading process is decipherment.
Now, let’s make it works. Supposed i have an oldskool 8051 development board with a 64 kilo-byte SRAM extension attached, and i wanted to protect the thing i stored in memory.
The 64 kbytes of SRAM takes 16-bits of address 8-bits of data with two additional control RD and WR. Here, as a prototype, we can use S-AES (a 16-bits block cipher with 16-bits of key) to scramble the address either in enciphering and deciphering mode. The 8-bits of content will be scrambled using S-DES (a 8-bits block cipher with 10-bits of key).
As a keying mechanism, the address scrambling will be keyed by a 17-bits key (16 from S-AES and 1 form encipherment/decipherment selection) while the content encipherment will be keyed by a 10-bits key with the addition of scrambled address to make the encipherment varies along the position. The total keyspace is 27-bit or about 128 million of combinations.
Here is the block diagram.

In real life, we need such two microcontrollers with 32 bits GPIO. The first microcontroller is responsible of scrambling the address using S-AES while the other one is responsible of scrambling the content using S-DES.
Haha, you know this is kinda stupid implementation, 27 bits of keyspace is to easy to break. It takes several seconds in a fast computer to brute force all combination. It’s just like nothing but who care
. I belief that this scheme works better at larger memory space such as 128-bit that enables the usage of AES.
. I belief that this scheme works better at larger memory space such as 128-bit that enables the usage of AES.
I am currently developing the software for both microcontroller. I chose AVR for simplicity reason. The code will be posted here and hosted athttp://cryptonutter.googlecode.com
2014年5月12日星期一
Attack on PUF
94% for 2-XOR PUF 15*10^3 CRPs
-------------------------------------------------------------------------------------------------
xorKnackertester(64, 2, 0.06, 0.06, 10, array([15000]), 'Test')
15000
features.shape is (2, 65, 15000)
testtargets.shape is (35000,)
1 1.0001 0.4908
1 .)
MCrate(train): 0.0586666666667 time since start: -0.354460000992
MCrate: (test) 0.0658571428571 time since start: -0.376991987228
features.shape is (2, 65, 15000)
testtargets.shape is (35000,)
1 1.0001 0.497533333333
1 .)
MCrate(train): 0.0588 time since start: -0.322597026825
MCrate: (test) 0.0693714285714 time since start: -0.345725059509
features.shape is (2, 65, 15000)
testtargets.shape is (35000,)
1 1.0001 0.494533333333
1 .)
MCrate(train): 0.0598666666667 time since start: -0.308412075043
MCrate: (test) 0.0674 time since start: -0.330398082733
features.shape is (2, 65, 15000)
testtargets.shape is (35000,)
1 1.0001 0.497666666667
1 .)
MCrate(train): 0.0596 time since start: -0.372863054276
MCrate: (test) 0.0676 time since start: -0.395931005478
features.shape is (2, 65, 15000)
testtargets.shape is (35000,)
1 1.0001 0.496666666667
1 .)
MCrate(train): 0.0584666666667 time since start: -0.432612895966
MCrate: (test) 0.0692285714286 time since start: -0.454550027847
features.shape is (2, 65, 15000)
testtargets.shape is (35000,)
1 1.0001 0.491066666667
1 .)
MCrate(train): 0.0587333333333 time since start: -0.406738996506
MCrate: (test) 0.0669714285714 time since start: -0.429100990295
features.shape is (2, 65, 15000)
testtargets.shape is (35000,)
1 1.0001 0.492866666667
1 .)
MCrate(train): 0.0572 time since start: -0.37618303299
MCrate: (test) 0.0676571428571 time since start: -0.398788928986
features.shape is (2, 65, 15000)
testtargets.shape is (35000,)
1 1.0001 0.498266666667
1 .)
MCrate(train): 0.0584 time since start: -0.393193006516
MCrate: (test) 0.0694 time since start: -0.416021108627
features.shape is (2, 65, 15000)
testtargets.shape is (35000,)
1 1.0001 0.501266666667
1 .)
MCrate(train): 0.056 time since start: -0.387744903564
MCrate: (test) 0.0669714285714 time since start: -0.409936904907
features.shape is (2, 65, 15000)
testtargets.shape is (35000,)
1 1.0001 0.512933333333
1 .)
MCrate(train): 0.0589333333333 time since start: -0.391460180283
MCrate: (test) 0.0664857142857 time since start: -0.413324117661
finished
-------------------------------------------------------------------------------------------------
-------------------------------------------------------------------------------------------------
xorKnackertester(64, 2, 0.06, 0.06, 10, array([15000]), 'Test')
15000
features.shape is (2, 65, 15000)
testtargets.shape is (35000,)
1 1.0001 0.4908
1 .)
MCrate(train): 0.0586666666667 time since start: -0.354460000992
MCrate: (test) 0.0658571428571 time since start: -0.376991987228
features.shape is (2, 65, 15000)
testtargets.shape is (35000,)
1 1.0001 0.497533333333
1 .)
MCrate(train): 0.0588 time since start: -0.322597026825
MCrate: (test) 0.0693714285714 time since start: -0.345725059509
features.shape is (2, 65, 15000)
testtargets.shape is (35000,)
1 1.0001 0.494533333333
1 .)
MCrate(train): 0.0598666666667 time since start: -0.308412075043
MCrate: (test) 0.0674 time since start: -0.330398082733
features.shape is (2, 65, 15000)
testtargets.shape is (35000,)
1 1.0001 0.497666666667
1 .)
MCrate(train): 0.0596 time since start: -0.372863054276
MCrate: (test) 0.0676 time since start: -0.395931005478
features.shape is (2, 65, 15000)
testtargets.shape is (35000,)
1 1.0001 0.496666666667
1 .)
MCrate(train): 0.0584666666667 time since start: -0.432612895966
MCrate: (test) 0.0692285714286 time since start: -0.454550027847
features.shape is (2, 65, 15000)
testtargets.shape is (35000,)
1 1.0001 0.491066666667
1 .)
MCrate(train): 0.0587333333333 time since start: -0.406738996506
MCrate: (test) 0.0669714285714 time since start: -0.429100990295
features.shape is (2, 65, 15000)
testtargets.shape is (35000,)
1 1.0001 0.492866666667
1 .)
MCrate(train): 0.0572 time since start: -0.37618303299
MCrate: (test) 0.0676571428571 time since start: -0.398788928986
features.shape is (2, 65, 15000)
testtargets.shape is (35000,)
1 1.0001 0.498266666667
1 .)
MCrate(train): 0.0584 time since start: -0.393193006516
MCrate: (test) 0.0694 time since start: -0.416021108627
features.shape is (2, 65, 15000)
testtargets.shape is (35000,)
1 1.0001 0.501266666667
1 .)
MCrate(train): 0.056 time since start: -0.387744903564
MCrate: (test) 0.0669714285714 time since start: -0.409936904907
features.shape is (2, 65, 15000)
testtargets.shape is (35000,)
1 1.0001 0.512933333333
1 .)
MCrate(train): 0.0589333333333 time since start: -0.391460180283
MCrate: (test) 0.0664857142857 time since start: -0.413324117661
finished
-------------------------------------------------------------------------------------------------
2014年4月25日星期五
Illustration of PUF model
Script
#execution of python files
from PUFmodels import *
reload (PUFmodels); from PUFmodels import *
test = XORArbPUF(10, 64, 'equal')
test.numXOR
test.calc_features(test.generate_challenge(4))
xorKnackertester(32, 2, 0.05, 0.01, 10, array([10000]), 'Test')
----------------------------------------------------------------------------
PUFmodels
# mathematic models of PUF
- linArbPUF
''' linArbPUF provides methods to simulate the behaviour of a standard
Arbiter PUF (linear model)
attributes:
num_bits -- bit-length of the PUF
delays -- runtime difference between the straight connections
(first half) and crossed connection (second half) in every switch
parameter -- parameter vector of the linear model (D. Lim)
'''
- XORArbPUF
'''
XOR of serveral independent PUFs
'''
----------------------------------------------------------------------------
xorKnackertester
# attack of XOR-PUF
- xorKnackertester
# just a interface to xorKnacker
- xorKnacker
model = prodLinearPredictor(bitzahl + 1, numxor) # the prodLinearPredictor used for prediction
lesson = BasicTrainable(set, model, erf) # use this model for BasicTrainable
In class prodLinearPredictor(object):
self.indiv_linpredictor = [linearPredictor(dim, mean, stdev) for i in range(num_prod)]
self.indiv_linpredictor[predictor].shift_param([indiv_step]) # it actually uses shift_param of linearPredictor to change param step by step
So it comes to the basic function below:
##########################
def shift_param(self, step):
''' change parameter by amount of step
Keyword Arguments:
step -- single element list of 1D array wth dimension as self.parameter
Side Effects:
changes the instance variable parameter
Exeptions:
DimensionError -- dimension of step and self.parameter do not match
'''
step = step[0]
if step.shape != self.parameter.shape:
raise DimensionError
else: self.parameter += step
##########################
Execution test:
>xorKnackertester(32, 2, 0.05, 0.01, 10, array([10000]), 'Test')
10000
1 1.0001 0.5036
1 .) MCrate(train): 0.01 time since start: -0.337867975235
MCrate: (test) 0.0142 time since start: -0.344507932663
# self.iteration_count, total_grad, train_performance
# performanceTrain, start - time.time()
# performanceTest, start - time.time()
1 1.0001 0.4804
1 .) MCrate(train): 0.0089 time since start: -0.33918094635
MCrate: (test) 0.0124 time since start: -0.345828056335
1 1.0001 0.5077
1 .) MCrate(train): 0.0099 time since start: -0.284085035324
MCrate: (test) 0.0131 time since start: -0.290790081024
1 1.0001 0.4823
1 .) MCrate(train): 0.0098 time since start: -0.339424133301
MCrate: (test) 0.0088 time since start: -0.354150056839
1 1.0001 0.4978
1 .) MCrate(train): 0.0095 time since start: -0.31689786911
MCrate: (test) 0.0137 time since start: -0.323953866959
1 1.0001 0.5251
1 .) MCrate(train): 0.0094 time since start: -0.344790935516
MCrate: (test) 0.0092 time since start: -0.351211071014
1 1.0001 0.5008
1 .) MCrate(train): 0.01 time since start: -0.369421005249
MCrate: (test) 0.0129 time since start: -0.376559019089
1 1.0001 0.4864
1 .) MCrate(train): 0.0096 time since start: -0.235582113266
MCrate: (test) 0.012 time since start: -0.242256164551
1 1.0001 0.4934
1 .) MCrate(train): 0.0099 time since start: -0.406064033508
MCrate: (test) 0.0127 time since start: -0.412713050842
1 1.0001 0.5061
1 .) MCrate(train): 0.0088 time since start: -0.28179192543
MCrate: (test) 0.0122 time since start: -0.288369894028
finished
<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<
First line printed:
print self.iteration_count, total_grad, train_performance :
train_performance = self.mc_error.calc(lesson.trainset.targets,
lesson.response()
) / lesson.trainset.targets.shape[0]
error = sum(1 - targets.squeeze() * sign(response.squeeze()) ) / 2
It is equivalent to (1- (right-wrong) )/2.
shape: size of array
----------------------------------------------------------------------------
light
- xorKnackertester
- xorKnacker
----------------------------------------------------------------------------
predictor
# prediction using different models, including learning methods
Model:
- linearPredictor
- prodLinearPredictor
- FFNeuralNet
- SVMmodel
Transfer function
- Sigmoid
- Tanh
error estimation
- LRError
- MSError
- MCError
- MCC
Learning function
- RProp
- GradientDescent
- AnealingGradientDescent
Train:
- Trainable
- BasicTrainable
- Learner
- GradLearner
- CrossValidation
- Closures
- TrainData
- SubSampling
#execution of python files
from PUFmodels import *
reload (PUFmodels); from PUFmodels import *
test = XORArbPUF(10, 64, 'equal')
test.numXOR
test.calc_features(test.generate_challenge(4))
xorKnackertester(32, 2, 0.05, 0.01, 10, array([10000]), 'Test')
----------------------------------------------------------------------------
PUFmodels
# mathematic models of PUF
- linArbPUF
''' linArbPUF provides methods to simulate the behaviour of a standard
Arbiter PUF (linear model)
attributes:
num_bits -- bit-length of the PUF
delays -- runtime difference between the straight connections
(first half) and crossed connection (second half) in every switch
parameter -- parameter vector of the linear model (D. Lim)
'''
- XORArbPUF
'''
XOR of serveral independent PUFs
'''
----------------------------------------------------------------------------
xorKnackertester
# attack of XOR-PUF
- xorKnackertester
# just a interface to xorKnacker
- xorKnacker
model = prodLinearPredictor(bitzahl + 1, numxor) # the prodLinearPredictor used for prediction
lesson = BasicTrainable(set, model, erf) # use this model for BasicTrainable
In class prodLinearPredictor(object):
self.indiv_linpredictor = [linearPredictor(dim, mean, stdev) for i in range(num_prod)]
self.indiv_linpredictor[predictor].shift_param([indiv_step]) # it actually uses shift_param of linearPredictor to change param step by step
So it comes to the basic function below:
##########################
def shift_param(self, step):
''' change parameter by amount of step
Keyword Arguments:
step -- single element list of 1D array wth dimension as self.parameter
Side Effects:
changes the instance variable parameter
Exeptions:
DimensionError -- dimension of step and self.parameter do not match
'''
step = step[0]
if step.shape != self.parameter.shape:
raise DimensionError
else: self.parameter += step
##########################
Execution test:
>xorKnackertester(32, 2, 0.05, 0.01, 10, array([10000]), 'Test')
10000
1 1.0001 0.5036
1 .) MCrate(train): 0.01 time since start: -0.337867975235
MCrate: (test) 0.0142 time since start: -0.344507932663
# self.iteration_count, total_grad, train_performance
# performanceTrain, start - time.time()
# performanceTest, start - time.time()
1 1.0001 0.4804
1 .) MCrate(train): 0.0089 time since start: -0.33918094635
MCrate: (test) 0.0124 time since start: -0.345828056335
1 1.0001 0.5077
1 .) MCrate(train): 0.0099 time since start: -0.284085035324
MCrate: (test) 0.0131 time since start: -0.290790081024
1 1.0001 0.4823
1 .) MCrate(train): 0.0098 time since start: -0.339424133301
MCrate: (test) 0.0088 time since start: -0.354150056839
1 1.0001 0.4978
1 .) MCrate(train): 0.0095 time since start: -0.31689786911
MCrate: (test) 0.0137 time since start: -0.323953866959
1 1.0001 0.5251
1 .) MCrate(train): 0.0094 time since start: -0.344790935516
MCrate: (test) 0.0092 time since start: -0.351211071014
1 1.0001 0.5008
1 .) MCrate(train): 0.01 time since start: -0.369421005249
MCrate: (test) 0.0129 time since start: -0.376559019089
1 1.0001 0.4864
1 .) MCrate(train): 0.0096 time since start: -0.235582113266
MCrate: (test) 0.012 time since start: -0.242256164551
1 1.0001 0.4934
1 .) MCrate(train): 0.0099 time since start: -0.406064033508
MCrate: (test) 0.0127 time since start: -0.412713050842
1 1.0001 0.5061
1 .) MCrate(train): 0.0088 time since start: -0.28179192543
MCrate: (test) 0.0122 time since start: -0.288369894028
finished
<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<
First line printed:
print self.iteration_count, total_grad, train_performance :
train_performance = self.mc_error.calc(lesson.trainset.targets,
lesson.response()
) / lesson.trainset.targets.shape[0]
error = sum(1 - targets.squeeze() * sign(response.squeeze()) ) / 2
It is equivalent to (1- (right-wrong) )/2.
shape: size of array
----------------------------------------------------------------------------
light
- xorKnackertester
- xorKnacker
----------------------------------------------------------------------------
predictor
# prediction using different models, including learning methods
Model:
- linearPredictor
- prodLinearPredictor
- FFNeuralNet
- SVMmodel
Transfer function
- Sigmoid
- Tanh
error estimation
- LRError
- MSError
- MCError
- MCC
Learning function
- RProp
- GradientDescent
- AnealingGradientDescent
Train:
- Trainable
- BasicTrainable
- Learner
- GradLearner
- CrossValidation
- Closures
- TrainData
- SubSampling
2014年4月24日星期四
Train SVM Classifiers Using a Custom Kernel
Ref: www.mathworks.nl/help/stats/support-vector-machines-svm.html#buax656-1a
Train SVM Classifiers Using a Custom Kernel
This example shows how to use a custom kernel function, such as the sigmoid kernel, to train SVM classifiers, and adjust custom kernel function parameters.Generate a random set of points within the unit circle. Label points in the first and third quadrants as belonging to the positive class, and those in the second and fourth quadrants in the negative class.
产生两个类型的元素,一个在 1/3相限,一个在2/4相限
rng(1); % For reproducibility n = 100; % Number of points per quadrant r1 = sqrt(rand(2*n,1)); % Random radii t1 = [pi/2*rand(n,1); (pi/2*rand(n,1)+pi)]; % Random angles for Q1 and Q3 X1 = [r1.*cos(t1) r1.*sin(t1)]; % Polar-to-Cartesian conversion r2 = sqrt(rand(2*n,1)); t2 = [pi/2*rand(n,1)+pi/2; (pi/2*rand(n,1)-pi/2)]; % Random angles for Q2 and Q4 X2 = [r2.*cos(t2) r2.*sin(t2)]; X = [X1; X2]; % Predictors Y = ones(4*n,1); Y(2*n + 1:end) = -1; % LabelsPlot the data.
figure;
gscatter(X(:,1),X(:,2),Y);
title('Scatter Diagram of Simulated Data')
Create the function mysigmoid.m, which accepts two matrices in the feature space as inputs, and transforms them into a Gram matrix using the sigmoid kernel.
%customized kernel, U*V' = r1*r2 * cos(t2-t1), when t2=t1, U*V' = r1*r2
%use tanh, because we want even small r1*r2 will also create effective desicion boundary, which means G = 1 or -1
function G = mysigmoid(U,V) % Sigmoid kernel function with slope gamma and intercept c gamma = 1; c = -1; G = tanh(gamma*U*V' + c); end
Train an SVM classifier using the sigmoid kernel function. It is good practice to standardize the data.
SVMModel1 = fitcsvm(X,Y,'KernelFunction','mysigmoid','Standardize',true);SVMModel is a ClassificationSVM classifier containing the estimated parameters.
Plot the data, and identify the support vectors and the decision boundary.
% Compute the scores over a grid d = 0.02; % Step size of the grid [x1Grid,x2Grid] = meshgrid(min(X(:,1)):d:max(X(:,1)),... min(X(:,2)):d:max(X(:,2))); xGrid = [x1Grid(:),x2Grid(:)]; % The grid [~,scores1] = predict(SVMModel1,xGrid); % The scores figure; h(1:2) = gscatter(X(:,1),X(:,2),Y); hold on h(3) = plot(X(SVMModel1.IsSupportVector,1),... X(SVMModel1.IsSupportVector,2),'ko','MarkerSize',10); % Support vectors contour(x1Grid,x2Grid,reshape(scores1(:,2),size(x1Grid)),[0 0],'k'); % Decision boundary title('Scatter Diagram with the Decision Boundary') legend({'-1','1','Support Vectors'},'Location','Best'); hold off
You can adjust the kernel parameters in an attempt to improve the shape of the decision boundary. This might also decrease the within-sample misclassification rate, but, you should first determine the out-of-sample misclassification rate.
Determine the out-of-sample misclassification rate by using 10-fold cross validation.
CVSVMModel1 = crossval(SVMModel1); misclass1 = kfoldLoss(CVSVMModel1); misclass1
misclass1 =
0.1350
The out-of-sample misclassification rate is 13.5%.Set gamma = 0.5; within mysigmoid.m. Then, train an SVM classifier using the adjusted sigmoid kernel. Plot the data and the decision region, and determine the out-of-sample misclassification rate.
SVMModel2 = fitcsvm(X,Y,'KernelFunction','mysigmoid','Standardize',true); [~,scores2] = predict(SVMModel2,xGrid); figure; h(1:2) = gscatter(X(:,1),X(:,2),Y); hold on h(3) = plot(X(SVMModel2.IsSupportVector,1),... X(SVMModel2.IsSupportVector,2),'ko','MarkerSize',10); title('Scatter Diagram with the Decision Boundary') contour(x1Grid,x2Grid,reshape(scores2(:,2),size(x1Grid)),[0 0],'k'); legend({'-1','1','Support Vectors'},'Location','Best'); hold off CVSVMModel2 = crossval(SVMModel2); misclass2 = kfoldLoss(CVSVMModel2); misclass2
misclass2 =
0.0450
After the sigmoid slope adjustment, the new decision boundary seems to provide a better within-sample fit, and the cross-validation rate contracts by more than 66%.
SVM material
关于SVM的那点破事[faruto长期更新整理]
简易目录:
写在前面的碎碎念;
Libsvm下载;
SVM入门;
Libsvm安装与使用(待完善);
SVM相关文献资料;
SVM相关书籍推荐;
SVM[Libsvm]相关应用(待完善);
SVM相关杂帖(待完善);
写在最后的闲扯淡;
Faruto的联系方式(讨论MATLAB相关问题或者具体一些SVM相关问题或者再具体一些libsvm使用相关问题或者再再具体一些 … …);
===================无聊的分隔线=========================
写在前面的碎碎念 by faruto
还记得初次接触SVM是本科大三的时候参加北师本科科研基金在管理学院系统科学那边做一个有关脑电波EEG模式识别的项目,那时候对于“机器学习” 这个概念还是头一次染指,后来使用libsvm工具箱来做分类和回归,在用的过程中来学习SVM底层的统计学习理论,再后来自己完善提升libsvm的 matlab版本,在林智仁先生的libsvm-mat基础上自己编写了一些辅助函数(参数寻优什么的),后来不断完善,最终自己的libsvm-mat 版本是libsvm-mat-2.89-3[FarutoUltimate3.0],方便自己使用以及论坛的一些朋友使用。
SVM的实现工具箱有很多,但我还是认为libsvm最好用(lssvm也不错的说),我认为把这一个SVM的实现工具箱研究的透彻就够了,反正我 是够用了,即如果现在需要SVM这个工具来进行分类或者回归我可以拿来libsvm-mat-2.89-3[FarutoUltimate3.0]就能熟 练使用以达到解决自己的问题的目的,而不用再重新学习掌握SVM这个工具。
其实还有一些话要说,姑且先留着吧 … …
====================
MATLAB技术论坛电子期刊第九期(2011.06)[faruto帖子集锦]
http://www.matlabsky.com/thread-17223-1-1.html
====================
《Learn SVM Step by Step 》系列视频应用篇
Libsvm的下载、安装和使用
http://www.matlabsky.com/thread-18080-1-1.html
Libsvm参数实例详解
http://www.matlabsky.com/thread-18457-1-1.html
一个实例搞定libsvm分类
http://www.matlabsky.com/thread-18521-1-1.html
一个实例搞定libsvm回归
http://www.matlabsky.com/thread-18552-1-1.html
Libsvm-mat林智仁先生的原始版本下载
libsvm官方更新[2011.04.01]:libsvm-3.1
http://www.matlabsky.com/thread-14345-1-1.html
libsvm-mat-2.91-1.zip
http://www.matlabsky.com/thread-9328-1-1.html
【说明:最新的版本为libsvm-mat-3.0-1.zip大家可以在这里下载http://www.csie.ntu.edu.tw/~cjlin/libsvm/ 最新版本的改动是将SVM的model structure移动到了svm.h里面,对于常规用户没有影响基本和以前的都一样,只是方便一些高级用户自己进行底层代码的修改】
Libsvm-mat faruto版本下载
(更新libsvm-faruto版本归来)libsvm-3.1-[FarutoUltimate3.1Mcode]
http://www.matlabsky.com/thread-17936-1-1.html
libsvm-mat-2.89-3[FarutoUltimate3.0]
http://www.matlabsky.com/thread-9327-1-1.html
GUI版本下载【基于libsvm-mat-2.89-3[FarutoUltimate3.0]】
[原创]SVM_GUI_2.0[mcode][by_faruto]
http://www.matlabsky.com/thread-9333-1-1.html
SVM入门
我个人推荐您看这个系列帖子
SVM入门精品系列讲解目录
http://www.matlabsky.com/thread-10317-1-1.html
共有10个系列讲解,很适合SVM入门。
[整理]Libsvm官方FAQ翻译
http://www.matlabsky.com/thread-15225-1-1.html
Libsvm安装与使用(待完善);
libsvm-mat在MATLAB平台下的安装【by faruto】
http://www.matlabsky.com/thread-11925-1-1.html
如何使用libsvm进行分类【by faruto】
http://www.matlabsky.com/thread-12379-1-1.html
如何使用libsvm进行回归预测【by faruto】
http://www.matlabsky.com/thread-12390-1-1.html
利用libsvm-mat建立分类模型model参数解密【by faruto】
http://www.matlabsky.com/thread-12649-1-1.html
libsvm如何使用自定义核函数[有关-t 4 参数的使用例子]
http://www.matlabsky.com/thread-15296-1-1.html
【转】Matlab中使用libsvm进行分类预测时的标签问题再次说明
http://www.matlabsky.com/thread-12396-1-1.html
基于GridSearch的svm参数寻优
http://www.matlabsky.com/thread-12411-1-1.html
基于GA的svm参数寻优
http://www.matlabsky.com/thread-12412-1-1.html
基于PSO的svm参数寻优
http://www.matlabsky.com/thread-12414-1-1.html
线性可分模式的最优超平面的详细推导过程【支持向量机相关】
http://www.matlabsky.com/thread-12613-1-1.html
libsvm 参数说明【中英文双语版本】
http://www.matlabsky.com/thread-12380-1-1.html
这部分过一段还要完善,目前关于libsvm的安装与使用可以参看以下资源
另外一篇:MATLAB自带的svm实现函数与libsvm差别小议
1 MATLAB自带的svm实现函数仅有的模型是C-SVC(C-support vector classification); 而libsvm工具箱有C-SVC(C-support vector classification),nu-SVC(nu-support vector classification),one-class SVM(distribution estimation),epsilon-SVR(epsilon-support vector regression),nu-SVR(nu-support vector regression)等多种模型可供使用。
2 MATLAB自带的svm实现函数仅支持分类问题,不支持回归问题;而libsvm不仅支持分类问题,亦支持回归问题。
3 MATLAB自带的svm实现函数仅支持二分类问题,多分类问题需按照多分类的相应算法编程实现;而libsvm采用1v1算法支持多分类。
4 MATLAB自带的svm实现函数采用RBF核函数时无法调节核函数的参数gamma,貌似仅能用默认的;而libsvm可以进行该参数的调节。
5 libsvm中的二次规划问题的解决算法是SMO;而MATLAB自带的svm实现函数中二次规划问题的解法有三种可以选择:经典二次方法;SMO;最小二乘。(这个是我目前发现的MATLAB自带的svm实现函数唯一的优点~)
参看在优酷上的一个有关libsvm的视频(这个是我以前在国内某论坛制作过的一个视频被网友放到了优酷上)
http://v.youku.com/v_show/id_XMTIwOTIzNTQ4.html
SVM相关文献资料
[flash]
http://player.youku.com/player.php/sid/XMTIwOTIzNTQ4/v.swf
[/flash]
关于SVM的理论相关的,在下面提供了一些资源和paper, ppt,pdf,虽然这几个资源是有限的,但我敢说足够了.原因有两个:a.下面的几个文献本身质量就很高.b.这些文献主要的SVM的参考文献已经几乎全部列出了,你可以寻径查找.
田英杰_支持向量回归机及其应用研究
http://www.matlabsky.com/thread-12841-1-1.html
Sequential Minimal Optimization for SVM
http://www.matlabsky.com/thread-13059-1-1.html
资料截图:
资料打包下载:
游客,如果您要查看本帖隐藏内容请回复
SVM相关书籍推荐
关于SVM的相关书籍,我个人首推这本书《MATLAB 神经网络30个案例分析》,因为我是这本书的作者之一,这本书的12-15章是有关SVM的,很不错的一本书,欢迎您购买
购买方式:
当当
http://product.dangdang.com/prod ... 07&ref=search-1-pub
china-pub
http://www.china-pub.com/50688
卓越
http://www.amazon.cn/mn/detailApp/ref=sr_1_1?_encoding=UTF8&s=books&qid=1287536439&asin=B003HGHB9W&sr=8-1
《MATLAB 神经网络30个案例分析》官方网站(可以额外购买书籍视频)
http://video.ourmatlab.com/
书籍视频销售客服QQ:1007911579
Matlab神经网络30个案例读者交流群
http://www.matlabsky.com/thread-14315-1-1.html
书籍目录
第1章 P神经网络的数据分类——语音特征信号分类1
第2章 BP神经网络的非线性系统建模——非线性函数拟合11
第3章 遗传算法优化BP神经网络——非线性函数拟合21
第4章 神经网络遗传算法函数极值寻优——非线性函数极值寻优36
第5章 基于BP_Adaboost的强分类器设计——公司财务预警建模45
第6章 PID神经元网络解耦控制算法——多变量系统控制54
第7章 RBF网络的回归——非线性函数回归的实现65
第8章 GRNN的数据预测——基于广义回归神经网络的货运量预测73
第9章 离散Hopfield神经网络的联想记忆——数字识别81
第10章 离散Hopfield神经网络的分类——高校科研能力评价90
第11章 连续Hopfield神经网络的优化——旅行商问题优化计算100
第12章 SVM的数据分类预测——意大利葡萄酒种类识别112
第13章 SVM的参数优化——如何更好的提升分类器的性能122
第14章 SVM的回归预测分析——上证指数开盘指数预测133
第15章 SVM的信息粒化时序回归预测——上证指数开盘指数变化趋势和变化空间预测141
第16章 自组织竞争网络在模式分类中的应用——患者癌症发病预测153
第17章 SOM神经网络的数据分类——柴油机故障诊断159
第18章 Elman神经网络的数据预测——电力负荷预测模型研究170
第19章 概率神经网络的分类预测——基于PNN的变压器故障诊断176
第20章 神经网络变量筛选——基于BP的神经网络变量筛选183
.第21章 LVQ神经网络的分类——乳腺肿瘤诊断188
第22章 LVQ神经网络的预测——人脸朝向识别198
第23章 小波神经网络的时间序列预测——短时交通流量预测208
第24章 模糊神经网络的预测算法——嘉陵江水质评价218
第25章 广义神经网络的聚类算法——网络入侵聚类229
第26章 粒子群优化算法的寻优算法——非线性函数极值寻优236
第27章 遗传算法优化计算——建模自变量降维243
第28章 基于灰色神经网络的预测算法研究——订单需求预测258
第29章 基于Kohonen网络的聚类算法——网络入侵聚类268
第30章 神经网络GUI的实现——基于GUI的神经网络拟合、模式识别、聚类277
========================================================
MATLAB神经网络30个案例分析 源代码+数据{SVM}[chapter12-15]
http://www.matlabsky.com/thread-11385-1-1.html
MATLAB神经网络30个案例分析 源代码+数据 大放送目录
http://www.matlabsky.com/thread-11479-1-1.html
========================================================
还有这本书也很不错~
《支持向量机--理论、算法与拓展》
作者: 邓乃扬 田英杰
出版社:科学出版社
ISBN:9787030250315
上架时间:2009-8-12
出版日期:2009 年8月
开本:16开
页码:244
版次:1-1
China-pub上的购买链接:http://www.china-pub.com/47322
SVM[Libsvm]相关应用(待完善)
基于libsvm的手写字体识别
http://www.matlabsky.com/thread-11025-1-1.html
基于libsvm的图像分割
http://www.matlabsky.com/thread-11026-1-1.html
基于SVM的基因选择(SVM-RFE算法)[SVM Recursive Feature Elimination (SVM RFE)]
基因选择算法SVM-RFE
http://www.matlabsky.com/thread-11568-1-1.html
基于平均影响值MIV的SVM变量筛选方法
http://www.matlabsky.com/thread-11569-1-1.html
基于SVM的语音特征信号分类
http://www.matlabsky.com/thread-11821-1-1.html
如何可视化libsvm的分类结果以及分类曲线
http://www.matlabsky.com/thread-12358-1-1.html
【转】文本分类入门(番外篇)特征选择与特征权重计算的区别
http://www.matlabsky.com/thread-12574-1-1.html
一些计划中将要发的帖子:
下几个帖子计划 掰饽饽说馅 的给大家说说
如何使用libsvm进行分类
如何使用libsvm进行回归
如何优化libsvm的各种参数
使用libsvm进行分类和回归的通常的流程以及注意事项
【
这个最有技术含量了,因为总有朋友说用libsvm做分类或者回归效果不好,我说把数据给我试一 下,结果我做的效果一般都会比其要好,为啥捏?这里先简单说一点点:使用libsvm(SVM)不是简简单单的用svmtrain输入几个参数 -c -g 生成model后用svmpredict来分类或者回归,其实更重要的是前期的数据预处理和后期的参数选择(归一化范围的选取,降维算法的选取,以及最佳 参数选取的算法)这些才是关键,其实说白了如果这些您都搞得很透彻的话,选择其他分类器也能做好,即这些(前期的数据预处理和后期的参数选择)做好了,选 择神马分类器真的并不重要,在libsvm-mat-2.89-3[FarutoUltimate3.0]工 具箱中我把常见的数据预处理方法(归一化,降维pca)和参数选择算法(grid search 暴力搜索方法,启发式GA、PSO方法)都封装好了方便大家使用,同样是用这个加强工具箱,但对于同一个测试数据集合,我敢保证肯定会有人用的效果就没有 我的好,为啥捏?因为知其然不知其所以然!肯定是其仅仅是了解一些表象的使用,而对于底层到底是怎么回事没有搞清楚,这样在具体的参数调整上肯定是不行 的,这也回答之前的“为什么总有朋友说用libsvm做分类或者回归效果不好,我说把数据给我试一下,结果我做的效果一般都会比其要好”的原因。
】
如何可视化libsvm的分类结果【虚幻的浮云~】
如何处理unbalanced label(不平衡数据标签)问题【难点问题】
SVM相关杂帖(待完善)
交叉验证(Cross Validation)方法思想简介
http://www.matlabsky.com/thread-10567-1-1.html
SVM的多分类问题
http://www.matlabsky.com/thread-9471-1-1.html
MATLAB数据归一化汇总(最全面的归一化介绍)
http://www.matlabsky.com/thread-9268-1-1.html
LibSVM程序代码注释详解
http://www.matlabsky.com/thread-9462-1-1.html
PSO资源整合工具箱
http://www.matlabsky.com/thread-9330-1-1.html
Matlab Toolbox for Dimensionality Reduction [降维工具箱]
http://www.matlabsky.com/thread-9335-1-1.html
TSVM(Transductive SVM)
http://www.matlabsky.com/thread-14257-1-1.html
Matlab神经网络30个案例读者交流群
http://www.matlabsky.com/thread-14315-1-1.html
关于matlab中princomp的使用说明讲解小例子【by faruto】
http://www.matlabsky.com/thread-11751-1-1.html
主成份分析PCA源代码
http://www.matlabsky.com/thread-11750-1-1.html
SVM相关QQ讨论群整理
http://www.matlabsky.com/thread-11971-1-1.html
2014年4月23日星期三
SVM
More formally, a support vector machine constructs a hyperplane or set of hyperplanes in a high-
or infinite-dimensional space, which can be used for classification,
regression, or other tasks. Intuitively, a good separation is achieved
by the hyperplane that has the largest distance to the nearest training
data point of any class (so-called functional margin), since in general
the larger the margin the lower the generalization error of the classifier.
Whereas the original problem may be stated in a finite dimensional space, it often happens that the sets to discriminate are not linearly separable in that space. For this reason, it was proposed that the original finite-dimensional space be mapped into a much higher-dimensional space, presumably making the separation easier in that space. To keep the computational load reasonable, the mappings used by SVM schemes are designed to ensure that dot products may be computed easily in terms of the variables in the original space, by defining them in terms of a kernel function
selected to suit the problem.[2]
The hyperplanes in the higher-dimensional space are defined as the set
of points whose dot product with a vector in that space is constant. The
vectors defining the hyperplanes can be chosen to be linear
combinations with parameters
of images of feature vectors that occur in the data base. With this choice of a hyperplane, the points
in the feature space that are mapped into the hyperplane are defined by the relation:
Note that if
becomes small as
grows further away from
, each term in the sum measures the degree of closeness of the test point
to the corresponding data base point
.
In this way, the sum of kernels above can be used to measure the
relative nearness of each test point to the data points originating in
one or the other of the sets to be discriminated. Note the fact that the
set of points
mapped into any hyperplane can be quite convoluted as a result,
allowing much more complex discrimination between sets which are not
convex at all in the original space.
However, not all sets of four points, no three collinear, are
linearly separable in two dimensions. The following example would need two straight lines and thus is not linearly separable:
Whereas the original problem may be stated in a finite dimensional space, it often happens that the sets to discriminate are not linearly separable in that space. For this reason, it was proposed that the original finite-dimensional space be mapped into a much higher-dimensional space, presumably making the separation easier in that space. To keep the computational load reasonable, the mappings used by SVM schemes are designed to ensure that dot products may be computed easily in terms of the variables in the original space, by defining them in terms of a kernel function
Linear separability
The problem of determining if a pair of sets is linearly separable and finding a separating hyperplane if they are arises in several areas. In statistics and machine learning, classifying certain types of data is a problem for which good algorithms exist that are based on this concept.
Three non-collinear points in two classes ('+' and '-') are always linearly separable in two dimensions. This is illustrated by the three examples in the following figure (the all '+' case is not shown, but is similar to the all '-' case):working env setting
When "command not found"
solution:
bin is in /software/bin/, Change /.bashrc, add path to it:
PATH=/usr/lib64/qt-3.3/bin:/usr/NX/bin:/usr/lib64/ccache:/usr/local/bin:/usr/bin:/bin:/usr/local/sbin:/usr/sbin:/sbin:/software/bin/
Done!
solution:
bin is in /software/bin/, Change /.bashrc, add path to it:
PATH=/usr/lib64/qt-3.3/bin:/usr/NX/bin:/usr/lib64/ccache:/usr/local/bin:/usr/bin:/bin:/usr/local/sbin:/usr/sbin:/sbin:/software/bin/
Done!
2014年4月21日星期一
PUF for more secure network
PUF
Let's take a broad view of present network. (PKI picture)
It's composed of key communication ,key protocol and key storage. ()
Take a look at authentication.
All in all, it's server-server authentication and server-client one. Based on protocols, on both sides, they have long-term private keys, so that it's guaranteed that we talk to the right people.
But there are something we should make sure: is the private key in the right hands? we focus on key storage here.
We have no doubt that the server can be under good surveillance, they got unlimited room, power and hardware for strong security. so private key of server is secure.
But what about smart card or handset? They need to be small, light, low power. Can they guarantee same standard of security as server? If not, then the whole client-server authentication is not secure.
Because in no matter symmetric authentication as MTI/A0 or RSA, if the private key of one-side is compromised, then the other side probably will talk with the wrong person - attacker. (MTI/A0, RSA protocol)
The problem with present key storage in client is its accessibility of device. Normally, they are stored in non-volatile memory such as ROM/EEPROM/Flash. But they are insecure. So we better figure out another way. (report article, french attack PPT )
Here we present a possible scheme with PUF as part of key storage.
Here what is stored not as plain private key, but a XOR of key with PUF-key. So even if it's read out, without any idea of PUF response, it will not leak any secret.Because the PUF CRPs stay inside the chip, no read-out it possible. (key storage scheme)
So why PUF are not readable? it's actually not stored, but a reflection of internal state which cannot be measured, they are process variation such as mos gate oxide thickness or something. Well, if they can be measured, that's would be disaster to PUF, actually more than PUF. (Process variation graph)
If we expand PUF the simple authentication, we can use this protocol.
well, we need to get PUF registered at first. Which is actually a readout of some CRPs. Then we cut the line, so no one are ever read again. During future authentication, every time the server send a random challenge to PUF, the PUF answers with responses.
There are a batch of things need to be dealt with
Let's take a broad view of present network. (PKI picture)
It's composed of key communication ,key protocol and key storage. ()
Take a look at authentication.
All in all, it's server-server authentication and server-client one. Based on protocols, on both sides, they have long-term private keys, so that it's guaranteed that we talk to the right people.
But there are something we should make sure: is the private key in the right hands? we focus on key storage here.
We have no doubt that the server can be under good surveillance, they got unlimited room, power and hardware for strong security. so private key of server is secure.
But what about smart card or handset? They need to be small, light, low power. Can they guarantee same standard of security as server? If not, then the whole client-server authentication is not secure.
Because in no matter symmetric authentication as MTI/A0 or RSA, if the private key of one-side is compromised, then the other side probably will talk with the wrong person - attacker. (MTI/A0, RSA protocol)
The problem with present key storage in client is its accessibility of device. Normally, they are stored in non-volatile memory such as ROM/EEPROM/Flash. But they are insecure. So we better figure out another way. (report article, french attack PPT )
Here we present a possible scheme with PUF as part of key storage.
Here what is stored not as plain private key, but a XOR of key with PUF-key. So even if it's read out, without any idea of PUF response, it will not leak any secret.Because the PUF CRPs stay inside the chip, no read-out it possible. (key storage scheme)
So why PUF are not readable? it's actually not stored, but a reflection of internal state which cannot be measured, they are process variation such as mos gate oxide thickness or something. Well, if they can be measured, that's would be disaster to PUF, actually more than PUF. (Process variation graph)
If we expand PUF the simple authentication, we can use this protocol.
well, we need to get PUF registered at first. Which is actually a readout of some CRPs. Then we cut the line, so no one are ever read again. During future authentication, every time the server send a random challenge to PUF, the PUF answers with responses.
There are a batch of things need to be dealt with
PUF as private key
PUF as private key will be weak, if
- PUF can be read out all of the CRPs
countermeasure:
(1) make CRPs large enough, that it takes much longer time to read out than its lifespan as ID.
- PUF can be attacked by limited CRPs, modeled to predict future CRPs
countermeasure:
(1) Hash challenges against choosing-text attack
(2) Hash response against modelling
- PUF can be cloned
countermeasure:
(1) ideal: cannot be modeled, such as optical PUF
(2) impossible to produce same PUF with assigned parameter. Since PUF parameter follows process variation which cannot be assigned or human manipulated, so it's by nature impossible.
(3) But can be achieved to have same CRPs with distinguished device such as PC or FPGA or MCU if already modeled.
Private key storage & Mutual authentication
1, Key storage security
Suppose Security(server) is better than Security(client), so only it's possible client private key can be compromised.
2, In MTI/A0 protocol
If it's server-server, it's secure.
but in a situation that it's client-server authentication, the private key of client a is compromised.
Then
a^x, a^y, a are known, but b in server is unknown, so it's not possible we can get the key.
Because, if the client store server public key a^b, even if the attack can get it, he cannot find b.
And he cannot get session key, because
session k = a^(ya+xb) = (a^y)^a * (a^x)^b
he hasn't got b, so no session key.
That's why it's mutual implicit key authentication. If you steal one private key= ID, you can just fake yourself as his ID and communicate on behalf of him, no the other side.
3, Conclusion, Mutual key authentication is secure, only if
Both private keys are secure, then no fake side;
But even if one key is compromised, no previous session key is compromised.
Suppose Security(server) is better than Security(client), so only it's possible client private key can be compromised.
2, In MTI/A0 protocol
If it's server-server, it's secure.
but in a situation that it's client-server authentication, the private key of client a is compromised.
Then
- previous communication will not be compromised, suppose the attacker just get eardropping information, because:
a^x, a^y, a are known, but b in server is unknown, so it's not possible we can get the key.
- The attacker cannot fake himself as server.
Because, if the client store server public key a^b, even if the attack can get it, he cannot find b.
And he cannot get session key, because
session k = a^(ya+xb) = (a^y)^a * (a^x)^b
he hasn't got b, so no session key.
That's why it's mutual implicit key authentication. If you steal one private key= ID, you can just fake yourself as his ID and communicate on behalf of him, no the other side.
3, Conclusion, Mutual key authentication is secure, only if
Both private keys are secure, then no fake side;
But even if one key is compromised, no previous session key is compromised.
2014年4月15日星期二
Infineon- Physically “Unclonable” Functions (PUF) - ready to serve government security?
July 4, 2013
Recently, so called Physically “Unclonable” Functions (PUF) received particular attention in the chip card market as a promising way to provide “silicon fingerprints”. Such structures could make electronic devices identifiable like biometrics do for human beings. As some early birds of this new PUF technology slowly mature from academic research to the implementation of prototypes, several severe security challenges become apparent that may jeopardize the promising ambitions of “silicon fingerprints”.
Current PUF implementations lack proof of security
Current security research demonstrates how Physically “Unclonable” Functions can indeed be cloned in a few hours (see e.g. link below: "Cloning Physically Unclonable Functions"). Next to that, a vast array of well-known attack classes has been successfully deployed against PUF implementations. For instance, PUFs have been attacked with side channel attacks (using the unintended leakage of secret information), fault attacks and physical manipulation of the chip. Manipulated PUF implementations have also been identified as a potential gateway for the introduction of Trojan Backdoors into security chips. In this case an assumed security function would in fact turn out to be a non-identifiable entrance for invaders.
PUF may introduce weaknesses to formerly secure systems
Applications with high security demand such as payment and government identification successfully rely on smart card solutions as solid root of trust since more than a decade. Independent certification schemes (e.g. Common Criteria & EMVCo) provide reliable security evidence that is up to date with the evolving attack methods. Adding PUF structures to smart cards used in these well proven applications may severely weaken the system security. Failures in such security critical applications are major risks for the governmental or commercial operators and can even put well established application classes into question.
Current PUF implementations potentially suited for low security applications
The verification of PUFs as “silicon fingerprints” in real products needs a safe playground that allows for learning without threatening valuable assets. PUFs in its current state should be used in low security applications and prototypes only. If early PUF implementations fail in large scale in critical systems, the whole technology may be at stake and the security industry and its customers will lose an opportunity for innovation.
The future of silicon identity
Secure identification or “fingerprinting” of chip card products is a strong requirement from many applications and has been addressed in different technical ways. Several solutions are already available as implementations that are independently security certified by Common Criteria. Further developments of “silicon biometrics“ show promising new technical properties and may contribute to raise the security level as soon as they have proven their reliability.
Please follow the links below to find references to additional material on the exciting prospects and challenges of silicon identity technologies that today are frequently referred to as “PUF”:
Cloning Physically unclonable Functions
Cloning the Unclonable
Literature Selection: PUF Attacks and Backdoor threats
Please feel free to contact us for further information: SiliconIdentity(at)infineon.com
Crypto presentation- prepare- key storage in OS
key storage
1, current key storage
hardware - NIST[3]
software- windows DPI [2] apple key chain[4] cloud storage [6] [8]
2, kerborus [5]
3, Validated FIPS 140-1 and FIPS 140-2 Cryptographic Modules [9]
[1] http://stackoverflow.com/questions/50142/symmetric-key-storage
[2] http://msdn.microsoft.com/en-us/library/ms995355.aspx
[3] NIST key storage
[4] http://en.wikipedia.org/wiki/Keychain_%28Apple%29
[5] http://www.cmf.nrl.navy.mil/krb/kerberos-faq.html#whatis
[6] https://developer.apple.com/library/safari/documentation/iphone/conceptual/safarijsdatabaseguide/name-valuestorage/name-valuestorage.html
[7] https://developer.apple.com/library/mac/documentation/General/Conceptual/iCloudDesignGuide/Chapters/DesigningForKey-ValueDataIniCloud.html
[8] http://tech-beta.slashdot.org/story/07/03/01/237209/secure-private-key-storage-for-unix
1, current key storage
hardware - NIST[3]
software- windows DPI [2] apple key chain[4] cloud storage [6] [8]
2, kerborus [5]
3, Validated FIPS 140-1 and FIPS 140-2 Cryptographic Modules [9]
[1] http://stackoverflow.com/questions/50142/symmetric-key-storage
[2] http://msdn.microsoft.com/en-us/library/ms995355.aspx
[3] NIST key storage
[4] http://en.wikipedia.org/wiki/Keychain_%28Apple%29
[5] http://www.cmf.nrl.navy.mil/krb/kerberos-faq.html#whatis
[6] https://developer.apple.com/library/safari/documentation/iphone/conceptual/safarijsdatabaseguide/name-valuestorage/name-valuestorage.html
[7] https://developer.apple.com/library/mac/documentation/General/Conceptual/iCloudDesignGuide/Chapters/DesigningForKey-ValueDataIniCloud.html
[8] http://tech-beta.slashdot.org/story/07/03/01/237209/secure-private-key-storage-for-unix
[9] http://csrc.nist.gov/groups/STM/cmvp/documents/140-1/140val-all.htm#1330
KDF- key derivation function
KDF用来从不安全的密码中生成安全的密码,实际上相当于加了个随机数salt,这样就使即使用户拥有相同的密码,依然有不同的加密结果。
In cryptography, a key derivation function (or KDF) derives one or more secret keys from a secret value such as a master key or other known information such as a password or passphrase using a pseudo-random function.[1][2] Keyed cryptographic hash functions are popular examples of pseudo-random functions used for key derivation.[3]
----------------------------------------------how salt works----------------------------------------------------------
Usually, when the user registers, you will generate a random value to become the salt. Then, in the user database, you store the user's name, salt, and hash generated using the password and salt (and whatever else is relevant for a user table).
Note that doing it this way allows each user to have a unique salt. Each user having a unique salt greatly increases attack difficulty. An attacker is forced to do a brute-force attack per user instead of precomputing per-password-scheme rainbow tables (no salts) or a per-database rainbow table (a system-wide salt). It is still your responsibility to make sure the brute force attack is actually slow enough to be costly to an attacker in these days of massively parallel GPU hash implementations.
Ideally, an attacker would not even be able to see the salt on the database, but it does not have to be private if worse comes to worse.
订阅:
博文 (Atom)
