首页> 外文会议>Business and Information Management, 2008. ISBIM '08 >An Online User Authentication Scheme for Web-Based services
【24h】

An Online User Authentication Scheme for Web-Based services

机译:基于Web的服务的在线用户身份验证方案

获取原文
获取外文期刊封面目录资料

摘要

Online user authentication using secure protocol is required by most web-based services. User authentication is mostly carried out by sending a pair of username and password to the server, since most users have not a certificate. Some attacks just rely on this fact, such as phishing attacks. In the paper, we discuss the issue of online user authentication and propose a method for online user authentication employing trusted computing technology. We describe a browser extension scheme, which transparently produces a certificate for each user, improving web authentication security and defending against password phishing and other attacks. Since the scheme combines the password entered by the user, the password associated with private key protected by trusted platform module, and user certificate provided by trusted computing platform, thieving only the password at web will not have an affect on user security. And no changes on the server side are required in the scheme. The proposed approach could be proved to protect against phishing attacks.
机译:大多数基于Web的服务都需要使用安全协议进行在线用户身份验证。由于大多数用户没有证书,因此用户身份验证通常是通过向服务器发送一对用户名和密码来执行的。一些攻击仅依赖于这一事实,例如网络钓鱼攻击。在本文中,我们讨论了在线用户身份验证的问题,并提出了一种使用可信计算技术进行在线用户身份验证的方法。我们描述了一种浏览器扩展方案,该方案可以透明地为每个用户生成一个证书,从而提高Web身份验证的安全性并防御密码网络钓鱼和其他攻击。由于该方案结合了用户输入的密码,与受信任平台模块保护的私钥相关联的密码以及由受信任计算平台提供的用户证书,因此仅在网络上窃取密码不会对用户安全产生影响。在该方案中,不需要在服务器端进行任何更改。可以证明所提出的方法可以防止网络钓鱼攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号