首页> 外文会议>International conference on financial cryptography and data security >Softer Smartcards Usable Cryptographic Tokens with Secure Execution
【24h】

Softer Smartcards Usable Cryptographic Tokens with Secure Execution

机译:具有安全执行功能的更软的智能卡可用的加密令牌

获取原文

摘要

Cryptographic smartcards provide a standardized, interoperable way for multi-factor authentication. They bridge the gap between strong asymmetric authentication and short, user-friendly passwords (PINs) and protect long-term authentication secrets against mal-ware and phishing attacks. However, to prevent malware from capturing entered PINs such cryptographic tokens must provide secure means for user input and output. This often makes their usage inconvenient, as dedicated input key pads and displays are expensive and do not integrate with mobile applications or public Internet terminals. The lack of user acceptance is perhaps best documented by the large variety of non-standard multi-factor authentication methods used in online banking. In this paper, we explore a novel compromise between tokens with dedicated card reader and USB or software-based solutions. We design and implement a cryptographic token using modern secure execution technology, resulting in a flexible, cost-efficient solution that is suitable for mobile use yet secure against common malware and phishing attacks.
机译:密码智能卡为多因素身份验证提供了一种标准化的,可互操作的方式。它们弥合了强非对称身份验证和简短的用户友好密码(PIN)之间的鸿沟,并保护了长期的身份验证机密,以防止恶意软件和网络钓鱼攻击。但是,为了防止恶意软件捕获输入的PIN,此类加密令牌必须为用户输入和输出提供安全的手段。由于专用的输入键盘和显示器价格昂贵并且不与移动应用程序或公共Internet终端集成,因此这常常使它们的使用不方便。网上银行中使用的多种非标准多因素身份验证方法可能最好地证明了用户接受度的不足。在本文中,我们探索了使用专用读卡器的令牌与基于USB或基于软件的解决方案之间的新颖折衷方案。我们使用现代的安全执行技术设计和实现加密令牌,从而提供了一种灵活,经济高效的解决方案,适用于移动应用,并且可以抵御常见的恶意软件和网络钓鱼攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号