【24h】

Secure Password Pocket for Distributed Web Services

机译:分布式Web服务的安全密码口袋

获取原文
获取原文并翻译 | 示例

摘要

Password authentication (PA) is a general and well-known technique to authenticate a user who is trying to establish a connection in distributed web services. The main idea of PA is to remove complex information from users so that they can log on servers only with a human-memorable password at anywhere. So far, many papers have been proposed to set up security requirements and improve the efficiency of PA. Most papers consider practical attacks such as password guessing, impersonation and server compromise which occur frequently in the real world. However, they missed an important and critical risk. A revealed password of a user from a server may affect other servers because most people tend to use a same password on different servers. This enables anyone who obtains a password to easily log onto other servers. In this paper, we first introduce a new notion, called "password pocket" which randomizes user's password even if he/she types a same password on different servers. When our password pocket is used, an exposed password does not affect other servers any more. The cost of a password pocket is extremely low since it needs to store only one random number securely.
机译:密码认证(PA)是一种通用的众所周知的技术,用于对试图在分布式Web服务中建立连接的用户进行认证。 PA的主要思想是从用户中删除复杂的信息,以便他们只能在任何地方使用易于记忆的密码登录服务器。到目前为止,已经提出了许多论文来建立安全性要求并提高PA的效率。大多数论文都考虑了现实中经常发生的实际攻击,例如密码猜测,假冒和服务器泄露。但是,他们错过了重要和关键的风险。用户从服务器公开的密码可能会影响其他服务器,因为大多数人倾向于在不同的服务器上使用相同的密码。这样,任何获得密码的人都可以轻松登录其他服务器。在本文中,我们首先介绍一个新的概念,称为“密码袋”,即使用户在不同的服务器上键入相同的密码,它也可以使用户的密码随机化。使用我们的密码袋后,暴露的密码不再影响其他服务器。密码袋的成本极低,因为它只需要安全地存储一个随机数即可。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号