首页> 外文会议>Irish Signals and Systems Conference >A novel approach for secure identity authentication in legacy database systems
【24h】

A novel approach for secure identity authentication in legacy database systems

机译:遗留数据库系统中用于安全身份认证的新颖方法

获取原文

摘要

Information systems in the digital age have become increasingly dependent on databases to store a multitude of fundamental data. A key function of structured databases is to house authentication credentials that verify identity and allow users to access more salient personal data. Authentication databases are frequently a target of attack as they potentially provide an avenue to commit further, more lucrative crimes. Despite the provision of industry standard best practice recommendations from organisations such as Open Web Application Security Project (OWASP), Payment Card Industry Security Standards Council (PCI-SSC), Internet Engineering Task Force (IETF) and Institute of Electrical and Electronics Engineers (IEEE), often practical security implementations within industry flounder. Lacking or substandard implementations have cultivated an environment where authentication databases and the data stored therein are insecure. This was demonstrated in the 2016 exposure of a breach experienced by Yahoo where approximately one billion user credentials were stolen. The global technology company was found to be using obsolete security mechanisms to protect user passwords. Dated implementations such as these pose serious threat as they render authentication data highly vulnerable to theft and potential misuse. This paper offers a novel solution for securing authentication databases on non-compliant Apache servers. The method applies the recommended best practice mechanisms in the form of salt, one-way encryption (hashing) and iterations to both pre-existing and newly created passwords that are stored on insecure systems. The proposed solution can be implemented server-side, with little alteration to the existing infrastructure, unbeknownst to the user. It possesses the potential to improve system security, aid compliance, preserve privacy and protect users.
机译:数字时代的信息系统越来越依赖于数据库来存储大量的基本数据。结构化数据库的关键功能是容纳身份验证凭据,以验证身份并允许用户访问更重要的个人数据。身份验证数据库通常是攻击的目标,因为它们潜在地提供了实施更多更有利可图的犯罪的途径。尽管提供了组织的行业标准最佳实践建议,例如开放Web应用程序安全项目(OWASP),支付卡行业安全标准委员会(PCI-SSC),互联网工程任务组(IETF)和电气电子工程师协会(IEEE) ),通常是行业难题中的实际安全性实现。缺乏或不合标准的实现方式已经建立了一个环境,在该环境中,身份验证数据库和其中存储的数据是不安全的。雅虎在2016年的一次泄密事件中证明了这一点,当时大约有10亿个用户凭据被盗。发现这家全球技术公司正在使用过时的安全机制来保护用户密码。诸如此类的过时的实现方式构成了严重的威胁,因为它们使身份验证数据极易受到盗窃和潜在滥用的影响。本文提供了一种新颖的解决方案,用于在不兼容的Apache服务器上保护身份验证数据库。该方法将盐,单向加密(散列)和迭代形式的推荐最佳实践机制应用于存储在不安全系统上的既有密码和新创建的密码。所提出的解决方案可以在服务器端实现,而对现有基础结构的改动很小,用户并不知道。它具有改善系统安全性,帮助合规性,保护隐私和保护用户的潜力。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号