Dodd, Charles John, Farshim, Pooya, Shahandashti, Siamak F. orcid.org/0000-0002-5284-6847 et al. (1 more author) (2026) Multi-Instance Unrecoverability of iMHF-Based Password Hashing. In: 31st European Symposium on Research in Computer Security. 31st European Symposium on Research in Computer Security, 14-18 Sep 2026 , ITA. (In Press)
Abstract
The study of memory-hard functions (MHFs) so far has mainly focused on providing provable guarantees on the expected minimum cumulative memory complexity (CMC) required per evaluation when amortized over multiple instances. Such results, however, do not provide any guarantees for the security of compromised password banks in the sense of passwords remaining unrecoverable. Indeed, a construction can be memory-hard while still leaking information about its input. We provide the first formal treatment of the unrecoverability of graph-based data-independent MHFs (iMHFs) in the multi-instance setting. Multi-instance security is the accepted security model when inputs have low-entropy or are correlated, and require the adversarial effort to linearly scale with the number of instances broken. To prove these results, we appropriately extend the ex-post-facto pebbling technique of Alwen and Serbinenko (STOC'15) and the unguessability reductions of Farshim and Tessaro (EUROCRYPT'21). We then use the resulting compatible frameworks to bound the number of guesses of adversaries with a given CMC in terms of the pebbling complexity of the graph underlying the iMHF. Combined with known lower bounds for the pebbling complexities of their graphs, we obtain, as corollaries, concrete unrecoverability bounds for the Argon2i, Catena, and Balloon hashing, showing in particular that the advantage indeed scales linearly with the number of instances and the cumulative memory complexity of the attacker.
Metadata
| Item Type: | Proceedings Paper |
|---|---|
| Authors/Creators: |
|
| Copyright, Publisher and Additional Information: | This is an author-produced version of the published paper. Uploaded in accordance with the University’s Research Publications and Open Access policy. |
| Keywords: | password hashing,memory-hard function,multi-instance security,cumulative memory complexity,pebbling complexity |
| Dates: |
|
| Institution: | The University of York |
| Academic Units: | The University of York > Faculty of Sciences (York) > Computer Science (York) |
| Date Deposited: | 11 Mar 2026 15:00 |
| Last Modified: | 11 Mar 2026 15:00 |
| Status: | In Press |
| Related URLs: | |
| Sustainable Development Goals: | |
| Open Archives Initiative ID (OAI ID): | oai:eprints.whiterose.ac.uk:238936 |
Download
Filename: Multi-Instance_Unrecoverability_of_iMHF-Based_Password_Hashing.pdf
Description: Multi-Instance Unrecoverability of iMHF-Based Password Hashing
Licence: CC-BY 2.5


CORE (COnnecting REpositories)
CORE (COnnecting REpositories)