.. DO NOT EDIT. .. THIS FILE WAS AUTOMATICALLY GENERATED BY SPHINX-GALLERY. .. TO MAKE CHANGES, EDIT THE SOURCE PYTHON FILE: .. "api/gallery/structures/hash_chains/plot_01_lamport_hash_chain.py" .. LINE NUMBERS ARE GIVEN BELOW. .. only:: html .. note:: :class: sphx-glr-download-link-note :ref:`Go to the end ` to download the full example code or to run this example in your browser via JupyterLite. .. rst-class:: sphx-glr-example-title .. _sphx_glr_api_gallery_structures_hash_chains_plot_01_lamport_hash_chain.py: Hash chains and one-time passwords (Lamport 1981) ================================================= Lamport proposed logging in without ever sending a reusable password. Hash a secret seed n times and give the server only the last value. Each login reveals the value before it: the server hashes it once and compares. A captured password is useless, because the next one is its *preimage*. This became S/KEY (1995), and hash chains reappear in blockchains as commit-reveal randomness and in Lamport-style signatures. What to look for ---------------- Each password verifies against the previous anchor, and the anchor moves back along the chain. Replaying a captured password fails, and the attacker cannot step backwards without inverting SHA-256. The history behind this experiment: :doc:`/history/structures_breakthroughs`. See :doc:`/exercises/structures` for a worked solution to the exercise. .. GENERATED FROM PYTHON SOURCE LINES 24-26 Log in five times ----------------- .. GENERATED FROM PYTHON SOURCE LINES 26-40 .. code-block:: Python import matplotlib.pyplot as plt import blockchainkit as bk chain = bk.structures.hash_chain(b"Alice's secret seed", 100) anchor = chain[-1] # Registered with the server once. used = [] for login in range(5): password = chain[-2 - login] assert bk.structures.verify_one_time_password(password, anchor) used.append(password) anchor = password # The server keeps the newest accepted value. print("5 logins accepted; the server now stores", anchor.hex()[:16], "...") .. rst-class:: sphx-glr-script-out .. code-block:: none 5 logins accepted; the server now stores 0768bbf7b5a19e83 ... .. GENERATED FROM PYTHON SOURCE LINES 41-43 A captured password cannot be replayed -------------------------------------- .. GENERATED FROM PYTHON SOURCE LINES 43-48 .. code-block:: Python eavesdropped = used[-1] assert not bk.structures.verify_one_time_password(eavesdropped, anchor) next_password = chain[-7] assert bk.crypto.sha256(next_password) == anchor # Only the seed holder can produce this. .. GENERATED FROM PYTHON SOURCE LINES 49-51 Remaining logins ---------------- .. GENERATED FROM PYTHON SOURCE LINES 51-58 .. code-block:: Python fig, ax = plt.subplots(figsize=(7, 3)) ax.barh( ["used", "remaining"], [len(used), len(chain) - 1 - len(used)], color=["#94a3b8", "#2563eb"] ) ax.set(xlabel="passwords", title="A chain of 100 hashes gives 99 logins") fig.tight_layout() .. image-sg:: /api/gallery/structures/hash_chains/images/sphx_glr_plot_01_lamport_hash_chain_001.png :alt: A chain of 100 hashes gives 99 logins :srcset: /api/gallery/structures/hash_chains/images/sphx_glr_plot_01_lamport_hash_chain_001.png :class: sphx-glr-single-img .. GENERATED FROM PYTHON SOURCE LINES 59-63 Exercise -------- Why must passwords be revealed in reverse order of computation? What does a server learn if it is breached, compared with storing a password hash? .. rst-class:: sphx-glr-timing **Total running time of the script:** (0 minutes 0.066 seconds) .. _sphx_glr_download_api_gallery_structures_hash_chains_plot_01_lamport_hash_chain.py: .. only:: html .. container:: sphx-glr-footer sphx-glr-footer-example .. container:: lite-badge .. image:: images/jupyterlite_badge_logo.svg :target: ../../../../lite/lab/index.html?path=api/gallery/structures/hash_chains/plot_01_lamport_hash_chain.ipynb :alt: Launch JupyterLite :width: 150 px .. container:: sphx-glr-download sphx-glr-download-jupyter :download:`Download Jupyter notebook: plot_01_lamport_hash_chain.ipynb ` .. container:: sphx-glr-download sphx-glr-download-python :download:`Download Python source code: plot_01_lamport_hash_chain.py ` .. container:: sphx-glr-download sphx-glr-download-zip :download:`Download zipped: plot_01_lamport_hash_chain.zip ` .. only:: html .. rst-class:: sphx-glr-signature `Gallery generated by Sphinx-Gallery `_