【24h】

Provably Secure Password Reset Protocol: Model, Definition, and Construction

机译:可能安全的密码重置协议:模型,定义和构造

获取原文
获取原文并翻译 | 示例

摘要

Many online services adopt a password-based user authentication system because of its usability. However, several problems have been pointed out on it, and one of the well-known problems is that a user forgets his/her password and cannot login the services. To solve this problem, most online services support a backup authentication mechanism with which a user can reset a password. However, negative facts about security have been reported for a popular backup authentication mechanism. In this paper, we consider a provable security treatment for a password reset protocol. First, we formalize a model and security definitions. We consider security against active adversaries that can mount man-in-the-middle attacks and concurrent attacks. Then we propose a generic construction of a password reset protocol secure under our definitions based on pseudorandom functions and public key encryption. In addition, we implement a prototype of our protocol to evaluate its efficiency.
机译:由于其可用性,许多在线服务都采用基于密码的用户身份验证系统。但是,已经指出了几个问题,其中一个众所周知的问题是用户忘记了他/她的密码而无法登录服务。为了解决此问题,大多数联机服务都支持备份身份验证机制,用户可以使用该机制来重置密码。但是,对于流行的备份身份验证机制,已经报道了有关安全性的负面事实。在本文中,我们考虑了密码重置协议的可证明安全性。首先,我们将模型和安全性定义形式化。我们考虑针对可能发起中间人攻击和并发攻击的活动对手的安全性。然后,我们根据伪随机函数和公共密钥加密的定义,提出了一种安全的密码重置协议的通用构造。此外,我们实现了协议的原型以评估其效率。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号