首页> 外文会议> >Mandatory human participation: a new authentication scheme for building secure systems
【24h】

Mandatory human participation: a new authentication scheme for building secure systems

机译:强制性的人类参与:用于构建安全系统的新认证方案

获取原文

摘要

Mandatory human participation (MHP) is a novel authentication scheme that asks the question "are you human?" (Instead of "who are you?"), and upon the correct answer to this question, can prove a principal to be a human being instead of a computer program. MHP helps solve old and new problems in computer security that existing security measures cannot address properly, including password (or PIN number) guessing attacks and application-level denial of service. A key component of this "are you human?" authentication process is a character morphing algorithm that transforms a character string into its graphical form in such a way that a human being won't have any problem recognizing the original string, while a computer program (e.g., an optical character recognition program), will not be able to decipher it or make a correct guess with nonnegligible probability. The basic idea of the MHP scheme is to ask an agent to recognize the string before its login attempts or transaction requests can be honored. Here a protocol is needed to send a puzzle to an agent, check if the answer supplied by the agent is correct, and most importantly make sure that the agent cannot cheat in the process. A number of system and security issues that relate to the protocol need to be addressed for the protocol to be secure, efficient, robust, and user-friendly. The MHP scheme contributes to the foundation of the computer security by faithfully implementing novel security semantics, "human," which existing cryptographic measures cannot express accurately. As many real-world security applications involve the interaction between a human and a computer, which naturally contains "human" as a part of its protocol semantics, we believe that the MHP scheme will find many new applications in the future.
机译:强制性人的参与(MHP)是一种询问问题的新型认证计划,“你是人类?” (而不是“你是谁?”),并且在这个问题的正确答案之上,可以证明一个人是人类而不是计算机程序。 MHP有助于解决计算机安全性的旧问题,即现有的安全措施无法正常地解决,包括猜测攻击和应用程序级别的密码(或引脚数)。这个关键的组成部分“你是谁?”身份验证过程是一种字符的变形算法,其将字符串转换为其图形形式,使得人类不会有识别原始字符串的任何问题,而计算机程序(例如,光学字符识别程序)将无法解密它或通过非中止概率进行正确的猜测。 MHP方案的基本思想是要求代理在其登录尝试或交易请求核准之前识别字符串。这里需要一个协议才能将拼图发送到代理,检查代理提供的答案是否正确,最重要的是确保代理商无法在此过程中作弊。需要解决与协议相关的许多系统和安全问题,以便协议安全,高效,强大,用户友好。 MHP方案通过忠实地实施新的安全语义,“人类”,为计算机安全性的基础有助于现有的加密措施无法准确表达。由于许多现实安全应用程序涉及人类和计算机之间的互动,它自然包含“人类”作为其协议语义的一部分,我们认为MHP方案将来会发现许多新应用。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号