Details

GeoVault: leveraging human spatial memory for secure cryptographic key management
ID Corn, Marko (Author), ID Podržaj, Primož (Author)

.pdfPDF - Presentation file, Download (623,60 KB)
MD5: 260DFE84DF1D5AB8F7C4A8B18256374C
URLURL - Source URL, Visit https://www.mdpi.com/2227-7390/14/10/1653 This link opens in a new window

Abstract
Practical failures of cryptographic key management rarely stem from weak algorithms: they arise from the difficulty users face in memorizing and reliably recalling high-entropy secrets. Password-based and brainwallet approaches collapse under selection bias, while machine-generated mnemonics such as BIP-39 impose a significant memory burden. This paper introduces GeoVault, a key derivation framework that uses remembered geographic locations as the cryptographic input. Keys are derived from a small set of user-selected map points, encoded deterministically using a geospatial scheme and hardened with the Argon2id memory-hard function. We develop a formal entropy model that distinguishes nominal from effective spatial entropy under attacker-prioritized geographic dictionaries and quantifies the additional reduction caused by demographic selection bias. Through information-theoretic analysis and CPU-GPU benchmarking, we show that spatial secrets carry a substantially higher effective entropy floor than human-chosen passwords, and that Argon2id creates a strong asymmetry between legitimate users and offline adversaries: at a memory cost of 1 GiB, an attacker using a high-end GPU can test approximately 66 candidate secrets per one defender key derivation. This residual throughput advantage is, however, overwhelmed by the exponential growth of the search space when multiple locations are selected. Selecting �≥3 geographic points is necessary and sufficient to achieve cryptographic-strength brute-force resistance under the global attacker prior across all evaluated Argon2id configurations. Against a demographically targeted attacker with city-level knowledge of the user, �=3 maintains Human-Scale Secure resistance; �=4 with a chaining depth of �=6 restores the Super Secure zone at an ≈8 s user-side wait. Single-point configurations remain insecure regardless of memory cost hardening.

Language:English
Keywords:cryptographic key management, spatial memory, mnemonic security, entropy modeling, memory-hard key derivation, Argon2, brainwallet security, human-centered cryptography
Work type:Article
Typology:1.01 - Original Scientific Article
Organization:FS - Faculty of Mechanical Engineering
Publication status:Published
Publication version:Version of Record
Year:2026
Number of pages:37 str.
Numbering:Vol. 14, issue 10, art. 1653
PID:20.500.12556/RUL-182654 This link opens in a new window
UDC:621.391:004.056.55
ISSN on article:2227-7390
DOI:10.3390/math14101653 This link opens in a new window
COBISS.SI-ID:278756867 This link opens in a new window
Publication date in RUL:20.05.2026
Views:254
Downloads:119
Metadata:XML DC-XML DC-RDF
:
Copy citation
Share:Bookmark and Share

Record is a part of a journal

Title:Mathematics
Shortened title:Mathematics
Publisher:MDPI AG
ISSN:2227-7390
COBISS.SI-ID:523267865 This link opens in a new window

Licences

License:CC BY 4.0, Creative Commons Attribution 4.0 International
Link:http://creativecommons.org/licenses/by/4.0/
Description:This is the standard Creative Commons license that gives others maximum freedom to do what they want with the work as long as they credit the author.

Secondary language

Language:Slovenian
Keywords:upravljanje kriptografskih ključev, prostorski spomin, varnost besednih zapisov, modeliranje entropije, pomnilniki

Projects

Funder:ARRS - Slovenian Research Agency
Project number:P2-0270
Name:Proizvodni sistemi, laserske tehnologije in spajanje materialov

Funder:Other - Other funder or multiple funders
Funding programme:Ministry of Higher Education, Science and Innovation of the Republic of Slovenia
Project number:100-15-0510

Similar documents

Similar works from RUL:
Similar works from other Slovenian collections:

Back