首页> 外文会议>Information Security Applications; Lecture Notes in Computer Science; 4298 >A Method and Its Usability for User Authentication by Utilizing a Matrix Code Reader on Mobile Phones
【24h】

A Method and Its Usability for User Authentication by Utilizing a Matrix Code Reader on Mobile Phones

机译:在手机上使用矩阵码阅读器进行用户认证的方法及其可用性

获取原文
获取原文并翻译 | 示例

摘要

Recently, the number of troubles about the user authentication for network services by phishing or spyware has been increasing. Utilizing hardware tokens such as IC cards, OTP cards, USB keys, or mobile phones are paid attention for making user authentications secure. However, most of the existing methods tend to take a lot of effort and costs for introducing hardware tokens. In addition, although the some methods are easy to be introduced, there are the problems about eavesdropping of the authentication information by malicious-ware such as key loggers. In this paper, we propose a user authentication method which does not need input and send the authentication information between a user terminal and a network service provider via the Internet, instead a one-time token that is issued by the provider and displayed as a matrix code on the user terminal, and the user reads the information with a matrix code reader on the user's mobile phone, and convert and transmit it to the provider via a comparatively trusted mobile phone carrier's network. The prototype system is implemented, and the user experiments which compare fix password type, two-factor one-time password type, and proposed type, were performed. As a result of a questionnaire about the usability, it was verified that the proposed method could impress users with comparatively high security and usability.
机译:近来,有关通过网络钓鱼或间谍软件进行网络服务的用户身份验证的麻烦数量正在增加。为了确保用户身份验证的安全,使用诸如IC卡,OTP卡,USB密钥或移动电话之类的硬件令牌已引起注意。但是,大多数现有方法在引入硬件令牌时往往会花费大量精力和成本。另外,尽管容易引入一些方法,但是存在诸如密钥记录器之类的恶意软件窃听认证信息的问题。在本文中,我们提出了一种用户身份验证方法,该方法不需要输入就可以通过Internet在用户终端和网络服务提供商之间发送身份验证信息,而是由提供商发行并显示为矩阵的一次性令牌。用户终端上的密码,用户使用用户手机上的矩阵阅读器读取信息,然后通过相对信任的手机运营商网络将其转换并传输给提供者。实现了原型系统,并进行了比较固定密码类型,两因素一次密码类型和建议类型的用户实验。通过对可用性的问卷调查,证实了该方法可以给用户带来较高的安全性和可用性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号