Shannon Information Entropy & Brute-Force Mathematical Formulations
Password resistance against offline exhaustive search attacks is quantified through Shannon entropy bits:
1. Shannon Password Entropy Formula
H = L × log₂(N) =
L × ln(N)ln(2)
2. Average Brute-Force Crack Duration Equation
T_crack =
N^L2 × R_guess
=2^(H - 1)R_guess
Step-by-Step Entropy Analysis Breakdown (Example: 12-char alphanumeric)
Step 1: Compute Character Pool Size (N)
N = 26 (lower) + 26 (upper) + 10 (digits) + 33 (symbols) = 95 characters
Step 2: Calculate Bits of Entropy
H = 12 × log₂(95) = 12 × 6.5698 = 78.84 bits of entropy
Step 3: Compute Expected Crack Duration at 10 Billion Guesses/sec
T_crack=≈ 851 Years to search 50% keyspace
Password Construction Models vs Entropy
| Type | Pattern Example | Entropy | Est. Crack Duration | Security Grade |
|---|---|---|---|---|
| Short Complex | P@ss1w0rd | ~40 bits | ~3 Hours | Inadequate |
| Long Complex | K8$mNp2#qL4x | ~79 bits | ~200 Years | Excellent |
| 4-Word Diceware | correct horse battery staple | ~51 bits | ~66 Years | Strong & Memorable |
| 5-Word Diceware | rapid tiger morning desk flute | ~64 bits | ~5,000 Years | Ultra-Secure |