【24h】

Zero-interaction authentication

机译:零交互身份验证

获取原文

摘要

Laptops are vulnerable to theft, greatly increasing the likelihood of exposing sensitive files. Unfortunately, storing data in a cryptographic file system does not fully address this problem. Such systems ask the user to imbue them with long-term authority for decryption, but that authority can be used by anyone who physically possesses the machine. Forcing the user to frequently reestablish his identity is intrusive, encouraging him to disable encryption.Our solution to this problem is Zero-Interaction Authentication, or ZIA. In ZIA, a user wears a small authentication token that communicates with a laptop over a short-range, wireless link. Whenever the laptop needs decryption authority, it acquires it from the token; authority is retained only as long as necessary. With careful key management, ZIA imposes an overhead of only 9.3% for representative workloads. The largest file cache on our hardware can be re-encrypted within five seconds of the user's departure, and restored in justover six seconds after detecting the user's return. This secures the machine before an attacker can gain physical access, but recovers full performance before a returning user resumes work.
机译:笔记本电脑容易被盗,从而大大增加了暴露敏感文件的可能性。不幸的是,将数据存储在密码文件系统中并不能完全解决此问题。这样的系统要求用户给他们长期的解密授权,但是任何实际拥有该机器的人都可以使用该授权。强迫用户频繁地重新建立自己的身份具有侵入性,鼓励他禁用加密。我们针对此问题的解决方案是零交互身份验证(即ZIA)。在ZIA中,用户佩戴一个小的身份验证令牌,该令牌通过短距离无线链路与便携式计算机进行通信。每当便携式计算机需要解密授权时,它都会从令牌中获取它。权限仅在必要时保留。通过精心的密钥管理,ZIA对代表性工作负载的开销仅为9.3%。我们硬件上最大的文件缓存可以在用户离开后的五秒钟内重新加密,并在检测到用户返回后的六秒钟内恢复。这可以在攻击者获得物理访问权之前保护计算机的安全,但是可以在返回用户恢复工作之前恢复全部性能。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号