Skip to main content

Posts

Hype and Media

The world badly requires a ‘hard-to-forget’, ‘hard-to-break’ and ‘panic-proof’ authentication measure. But the media are continually promoting the hypes. Sadly, it seems that so many biz/tech media are so heavily dependent on the ad money from super-spreaders of hypes who are very rich from spreading hypes. Quick Money from False Sense of Security – Ethically Dubious Business Practice - https://www.linkedin.com/pulse/quick-money-from-false-sense-security-ethically-dubious-kokumai/

Global Headquarters in United Kingdom

Having been talking for some time about the headquarters to be set up for global operations of Expanded Password System (EPS), we have now chosen UK as the venue in view of its reputed R&D infrastructure. We are putting together diverse brains from multiple disciplines - psychology, sociology, behavioral economics as well as tamper-proof programming, cryptography and other security-intelligence technologies in the common language in view of our mission of globally promoting identity assurance by our own volition and memory for secure digital identity in post-pandemic cyberspace, The aim of our enterprise is to make EPS solutions readily available to all the global citizens: rich and poor, young and old, healthy and disabled, literate and illiterate, in peace and in disasters. Here is a summary and brief history of Expanded Password System since 2000 when I first thought of making use of our episodic image memory for identity authentication. Key references are mentione...

Expanded Password System – Theory and Implementation

Expanded Password System, however solid the theory is, would be vulnerable to attacks when it is poorly implemented. Very fortunately, our first client in Japan who adopted Expanded Password System for 140,000 shoppers (designed for one million users) was extremely demanding about the implementation.   We had to satisfy them and actually satisfied them with the solid implementation.   Another major client is Japanese army. We naturally had to be very confident about the good implementation. For both theory and implementation, we owe a lot to Emeritus Prof. Hideki Imai, who was the chairperson of Japan’s CRYPTREC and also a cryptography advisor to the defense forces when we first met in 2001.   He pushed my back to move ahead confidently with promotion of Expanded Password System, and helped me a lot with several joint research programs until he retired from Tokyo University. It is from him that I came to know about the likes of Elliptic Curve Cryptography. E...

Who Adopted Expanded Password System (EPS) and for What

A telecom company who built a payment system designed for a million online shoppers adopted EPS for accepting ‘Hard-to-Forget’ and yet ‘Hard-to-Break’ credentials and for reducing the helpdesk cost drastically. Actually 140,000 online shoppers enjoyed the no friction login before the payment system was closed in 2008. An IT corporation who built a security-conscious corporate network adopted EPS deployed in 2-channel/2-factor scheme for accepting ‘Very Hard-to-Break’ and yet ‘Hard-to-Forget’ credentials. 1,200 employees are still enjoying the good balance of security and usability. Japan’s Self-Defense Ground Forces, aka Army, adopted our product for accepting ‘Panic-Proof’ and yet ‘Hard-to-Break’ credentials. The number of licenses has increased more than 10-fold over the 7-year period from 2013 and is set to increase further. We expect to see similar adoptions in hundreds or thousands of times larger scale once we start the operation in the global market from the headqu...

Cryptography and Expanded Password System

Prof. Hideki Imai, who pushed my back to move ahead confidently in 2001 when he was the chair of Japan’s CRYPTREC, used to emphasize repeatedly how critical it is to get the credential data hashed whether online or offline. It is from him that I learnt about Deffie-Hellman Key Exchange, Elliptic Curve Cryptography, etc. We jointly tried the methodology of using the high-entropy credential data generated by Expanded Password System (EPS) as the seed of RSA key pair; the user's private key does not physically exist anywhere in the universe, but it can be re-generated in-the-fly out of the images that the user picks up for authentication for each login. It proved to work on the internet. Thereafter, we took up the experiment of incorporating EPS into PAKE.   We were able to demonstrate that it worked with no friction in the lab environment. These projects, sponsored by government agencies, were completed in 2003 – 2004.   In retrospect, we seem to have started these...

Default Password and Fallback Password

It appears that quite a few biometrics people confidently allege that they do not rely on a fallback password or any backup measure. In most cases, judging from my experience of dealing with biometrics people for nearly 20 years, those people are simply indifferent to the fact that the default password, which was quietly embedded in their authentication systems from the beginning, functions as a fallback password when the user gets rejected by the biometrics. Here, indifference and ignorance might be one of their most powerful weapons for their active sales operations. https://www.linkedin.com/pulse/early-models-smartphones-were-safer-than-newer-how-come-kokumai

On-the-fly Key Regeneration

I referred to ‘on-the-fly’ key regeneration in my earlier post “Cryptography and Expanded Password System” - https://www.linkedin.com/posts/hitoshikokumai_identity-authentication-password-activity-6678120452411531264-tfCF The core logic is so simple and plain that this non-technology man was able to come up with overnight. I do not think it needs to be kept confidential. Each image is represented by a very long identifier data.   The entropy of the identifier data summed up out of the several images the use picks up is very high to the extent that it works as the seed for generating unique encryption key. Once the key gets generated and used for encryption, the seed and key will be eliminated while the software program remembers the formula for calculation.   For decryption, the user picks up the correct images, the identifier data getting summed up to generate the seed, which will be put into the formula to calculate the key.   The seed and key will be ...