首页> 外文会议>International World Wide Web Conference; 20050510-14; (JP) >A Convenient Method for Securely Managing Passwords
【24h】

A Convenient Method for Securely Managing Passwords

机译:安全管理密码的便捷方法

获取原文
获取原文并翻译 | 示例
获取外文期刊封面目录资料

摘要

Computer users are asked to generate, keep secret, and recall an increasing number of passwords for uses including host accounts, email servers, e-commerce sites, and online financial services. Unfortunately, the password entropy that users can comfortably memorize seems insufficient to store unique, secure passwords for all these accounts, and it is likely to remain constant as the number of passwords (and the adversary's computational power) increases into the future. In this paper, we propose a technique that uses a strengthened cryptographic hash function to compute secure passwords for arbitrarily many accounts while requiring the user to memorize only a single short password. This mechanism functions entirely on the client; no server-side changes are needed. Unlike previous approaches, our design is both highly resistant to brute force attacks and nearly stateless, allowing users to retrieve their passwords from any location so long as they can execute our program and remember a short secret. This combination of security and convenience will, we believe, entice users to adopt our scheme. We discuss the construction of our algorithm in detail, compare its strengths and weaknesses to those of related approaches, and present Password Multiplier, an implementation in the form of an extension to the Mozilla Firefox web browser.
机译:要求计算机用户生成,保密和重新调用越来越多的密码,以用于主机帐户,电子邮件服务器,电子商务站点和在线金融服务。不幸的是,用户可以轻松记住的密码熵似乎不足以为所有这些帐户存储唯一安全的密码,并且随着密码数量(以及对手的计算能力)在未来增加,它可能保持不变。在本文中,我们提出了一种技术,该技术使用增强的加密哈希函数来计算任意多个帐户的安全密码,同时要求用户仅存储一个短密码。该机制完全在客户端上起作用。无需服务器端更改。与以前的方法不同,我们的设计既具有高度的抵抗暴力攻击的能力,又具有近乎无状态的特性,只要用户可以执行我们的程序并记住一个简短的秘密,就可以从任何位置检索密码。我们相信,安全性和便利性的结合会吸引用户采用我们的方案。我们将详细讨论算法的构造,将其优点和缺点与相关方法的优点和缺点进行比较,并提出密码乘数,它是对Mozilla Firefox Web浏览器的扩展形式。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号