【24h】

Robust password system based on dynamic factors

机译:基于动态因素的强大密码系统

获取原文
获取原文并翻译 | 示例

摘要

Knowledge-based authentication systems have several drawbacks, but many systems, such as Facebook and Bank of America, still use this method to authenticate legitimate users. Traditional passwords can be easily compromised and the security process jeopardized. More specifically, hackers can capture password information on a network and replay it to gain unauthorized access to a system. Knowledge-based systems that simply use a password are susceptible to this replay attack. This research proposes a new password protocol that improves password security and mitigates replay attacks. Instead of a single static password to authenticate an individual, passwords are created based on a user's input as well as a random ordering of internal and external factors such as system time and weather. A hacker can capture a password generated by one set of factors, but a replay attack will be mitigated due to the non-deterministic factor order. This research proposes a dynamic system architecture that makes any captured data worthless.
机译:基于知识的身份验证系统有几个缺点,但是许多系统(例如Facebook和美国银行)仍然使用此方法来验证合法用户。传统密码很容易遭到破坏,安全过程受到威胁。更具体地说,黑客可以捕获网络上的密码信息并重播该密码信息,以获取对系统的未授权访问。仅使用密码的基于知识的系统容易受到此重放攻击。这项研究提出了一种新的密码协议,可以提高密码安全性并减轻重放攻击。根据用户的输入以及内部和外部因素(例如系统时间和天气)的随机顺序,可以创建密码,而不是使用单个静态密码来验证个人身份。黑客可以捕获由一组因素生成的密码,但是由于不确定的因素顺序,因此可以缓解重播攻击。这项研究提出了一种动态系统体系结构,该体系结构使捕获的数据毫无价值。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号