首页> 外文会议>Irish Signals and Systems Conference >A novel approach for secure identity authentication in legacy database systems
【24h】

A novel approach for secure identity authentication in legacy database systems

机译:一种在传统数据库系统中安全身份认证的新方法

获取原文

摘要

Information systems in the digital age have become increasingly dependent on databases to store a multitude of fundamental data. A key function of structured databases is to house authentication credentials that verify identity and allow users to access more salient personal data. Authentication databases are frequently a target of attack as they potentially provide an avenue to commit further, more lucrative crimes. Despite the provision of industry standard best practice recommendations from organisations such as Open Web Application Security Project (OWASP), Payment Card Industry Security Standards Council (PCI-SSC), Internet Engineering Task Force (IETF) and Institute of Electrical and Electronics Engineers (IEEE), often practical security implementations within industry flounder. Lacking or substandard implementations have cultivated an environment where authentication databases and the data stored therein are insecure. This was demonstrated in the 2016 exposure of a breach experienced by Yahoo where approximately one billion user credentials were stolen. The global technology company was found to be using obsolete security mechanisms to protect user passwords. Dated implementations such as these pose serious threat as they render authentication data highly vulnerable to theft and potential misuse. This paper offers a novel solution for securing authentication databases on non-compliant Apache servers. The method applies the recommended best practice mechanisms in the form of salt, one-way encryption (hashing) and iterations to both pre-existing and newly created passwords that are stored on insecure systems. The proposed solution can be implemented server-side, with little alteration to the existing infrastructure, unbeknownst to the user. It possesses the potential to improve system security, aid compliance, preserve privacy and protect users.
机译:数字时代的信息系统越来越依赖于数据库来存储多种基本数据。结构化数据库的一个关键功能是容纳验证身份的身份验证凭据,并允许用户访问更加突出的个人数据。身份验证数据库通常是攻击的目标,因为它们可能提供途径以进一步提交,更有利可图的罪行。尽管从开放的Web应用程序安全项目(OWASP),支付卡行业安全标准委员会(PCI-SSC),互联网工程工作组(IETF)和电气和电子工程师协会(IEEE),仍提供行业标准的最佳实践建议),通常在行业比较中实际的安全实施。缺乏或不合标准的实现培养了一个身份验证数据库和存储在其中的数据的环境是不安全的。这是在2016年的违规风险违规的违约之中展示,其中大约十亿个用户凭证被盗。发现全球技术公司正在使用过时的安全机制来保护用户密码。诸如这些构成严重威胁的日期实现,因为它们呈现了高度易受盗窃和潜在滥用的认证数据。本文提供了一种用于在不合规Apache服务器上保护身份验证数据库的新型解决方案。该方法以盐,单向加密(散列)和迭代的形式应用于存储在不安全系统上的预先存在的和新创建的密码的推荐最佳实践机制。所提出的解决方案可以实现服务器端,对现有基础架构的更改很少,对用户不知数。它拥有改善系统安全性,援助合规性,保护隐私和保护用户的潜力。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号