首页> 外文会议>Information security and privacy >One-Time-Password-Authenticated Key Exchange
【24h】

One-Time-Password-Authenticated Key Exchange

机译:一次性密码认证的密钥交换

获取原文
获取原文并翻译 | 示例

摘要

To reduce the damage of phishing and spyware attacks, banks, governments, and other security-sensitive industries are deploying onetime password systems, where users have many passwords and use each password only once. If a single password is compromised, it can be only be used to impersonate the user once, limiting the damage caused. However, existing practical approaches to one-time passwords have been susceptible to sophisticated phishing attacks. We give a formal security treatment of this important practical problem. We consider the use of one-time passwords in the context of password-authenticated key exchange (PAKE), which allows for mutual authentication, session key agreement, and resistance to phishing attacks. We describe a security model for the use of one-time passwords, explicitly considering the compromise of past (and future) one-time passwords, and show a general technique for building a secure one-time-PAKE protocol from any secure PAKE protocol. Our techniques also allow for the secure use of pseudorandomly generated and time-dependent passwords.
机译:为了减少网络钓鱼和间谍软件攻击的危害,银行,政府和其他对安全敏感的行业正在部署一次性密码系统,该系统中用户拥有许多密码,并且每个密码只能使用一次。如果单个密码被泄露,则只能用于模拟用户一次,从而限制了造成的损失。但是,现有的一次性密码实用方法容易受到复杂的网络钓鱼攻击。我们对这个重要的实际问题给予正式的安全处理。我们考虑在经过密码身份验证的密钥交换(PAKE)的上下文中使用一次性密码,该密码允许相互身份验证,会话密钥协定以及对网络钓鱼攻击的抵抗力。我们描述了一种使用一次性密码的安全模型,明确考虑了过去(和将来)一次性密码的危害,并展示了一种从任何安全的PAKE协议构建安全的一次性PAKE协议的通用技术。我们的技术还允许安全使用伪随机生成的和时间相关的密码。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号