【24h】

Research of authentication mechanism in CHAP

机译:CHAP中认证机制的研究

获取原文

摘要

The method of double-factor authentication is usually embedded in CHAP (Challenge Handshake Authentication Protocol) to enhance the security of the authentication service. The CHAP protocol with double-factor authentication is formally verified from the intruder's aspect, and some data structures is abstracted from the protocol to build up the framework of reasoning-logic. By the means of adverse deduction, the framework of reasoning-logic is analyzed thoroughly, the flaws of the CHAP protocol is found and the corresponding attacking scenario is given. The result shows that the CHAP protocol with double-factor authentication has some security holes and can't achieve the security requirement of the design.
机译:双重身份验证方法通常嵌入CHAP(挑战握手身份验证协议)中,以增强身份验证服务的安全性。从入侵者的角度对具有双因素身份验证的CHAP协议进行了形式验证,并从该协议中抽象了一些数据结构以构建推理逻辑框架。通过逆向推论,对推理逻辑框架进行了深入分析,发现了CHAP协议的缺陷,并给出了相应的攻击场景。结果表明,采用双因素认证的CHAP协议存在一定的安全漏洞,无法达到设计的安全要求。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号