首页> 外文会议>Information Security and Privacy >Enforcing User-Aware Browser-Based Mutual Authentication with Strong Locked Same Origin Policy
【24h】

Enforcing User-Aware Browser-Based Mutual Authentication with Strong Locked Same Origin Policy

机译:使用强锁定的相同起源策略来实施基于用户的基于浏览器的相互身份验证

获取原文
获取原文并翻译 | 示例

摘要

The standard solution for mutual authentication between human users and servers on the Internet is to execute a TLS handshake during which the server authenticates using a X.509 certificate followed by the authentication of the user either with own password or with some cookie stored within the user's browser. Unfortunately, this solution is susceptible to various impersonation attacks such as phishing as it turned out that average Internet users are unable to authenticate servers based on their certificates. In this paper we address security of cookie-based authentication using the concept of strong locked same origin policy for browsers introduced at ACM CCS'07. We describe a cookie-based authentication protocol between human users and TLS-servers and prove its security in the extended formal model for browser-based mutual authentication introduced at ACM ASIACCS'08. It turns out that the small modification of the browser's security policy is sufficient to achieve provably secure cookie-based authentication protocols considering the ability of users to recognize images, video, or audio sequences.
机译:互联网上人类用户与服务器之间的相互身份验证的标准解决方案是执行TLS握手,在此期间,服务器使用X.509证书进行身份验证,然后使用自己的密码或使用用户内部存储的某些cookie对用户进行身份验证。浏览器。不幸的是,该解决方案易受各种模拟攻击的攻击,例如网络钓鱼,因为事实证明,普通的Internet用户无法根据其证书对服务器进行身份验证。在本文中,我们使用针对ACM CCS'07引入的浏览器的强锁定同源策略的概念来解决基于cookie的身份验证的安全性。我们描述了人类用户和TLS服务器之间基于cookie的身份验证协议,并在ACM ASIACCS'08上针对基于浏览器的相互身份验证的扩展正式模型中证明了其安全性。事实证明,考虑到用户识别图像,视频或音频序列的能力,对浏览器的安全策略进行小的修改就足以实现可验证的基于cookie的安全验证协议。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号