首页> 外文会议>International Symposium on Networks, Computers and Communications >A Novel Approach for Protecting Legacy Authentication Databases in Consideration of GDPR
【24h】

A Novel Approach for Protecting Legacy Authentication Databases in Consideration of GDPR

机译:考虑到GDPR的传统认证数据库保护遗留认证数据库的新方法

获取原文

摘要

The upcoming implementation of the European Union General Data Protection Regulation (GDPR) will require many organisations throughout the EU to comply with new requirements that are intended to better protect personal data. Large increases in responsibility, penalties and fines will place great pressure on organisations to ensure they are compliant and adequately protect user data that is associated with online accounts. Non-compliant legacy databases are those that store authentication credentials in plaintext or utilizing obsolete one-way encryption techniques that fail to adhere to best practice guidelines. Companies who remain reliant on these vulnerable systems will be forced to reconsider and improve their architecture, or risk the exposure of personal data and the debilitating penalties that will also be incurred. Authentication databases are frequently a target of attack as they potentially provide an avenue to commit further, more lucrative crimes. Lacking or substandard implementations have cultivated an environment where authentication databases and the data stored therein are insecure. This was demonstrated in the 2016 exposure of a breach experienced by Yahoo where approximately one billion user credentials were stolen. The global technology company was found to be using obsolete security mechanisms to protect user passwords. This paper offers a novel solution for improving the protection of currently non-compliant legacy authentication databases stored on Apache servers. The method applies best practice mechanisms in the form of salt, one-way encryption (hashing) and iterations to both pre-existing and newly created passwords held within the databases. The proposed solution can be implemented server-side, with little alteration to the existing infrastructure and unbeknownst to the user. It possesses the potential to improve system security, preserve privacy, and aid implementation of GDPR requirements.
机译:即将到来的欧盟一般数据保护条例(GDPR)将在整个欧盟中要求许多组织遵守旨在更好地保护个人数据的新要求。责任的巨大增加,罚款和罚款将对组织提出很大的压力,以确保它们符合和充分保护与在线账户相关联的用户数据。不合规的传统数据库是那些以明文存储身份验证凭据的数据库,或利用未能遵守最佳实践指南的过时单向加密技术。保持依赖于这些弱势系统的公司将被迫重新考虑并改善其架构,或者冒着个人数据的曝光风险以及也将产生的衰弱罚款。身份验证数据库通常是攻击的目标,因为它们可能提供途径以进一步提交,更有利可图的罪行。缺乏或不合标准的实现培养了一个身份验证数据库和存储在其中的数据的环境是不安全的。这是在2016年的违规风险违规的违约之中展示,其中大约十亿个用户凭证被盗。发现全球技术公司正在使用过时的安全机制来保护用户密码。本文提供了一种新的解决方案,可改进存储在Apache服务器上的当前不合规的遗留识别数据库的保护。该方法以盐,单向加密(散列)和迭代的形式应用于预先存在的和新创建的密码,应用于数据库中的预先存在和新创建的密码。所提出的解决方案可以实现服务器端,对现有的基础架构和用户不知数几乎没有更改。它拥有改善系统安全,保护隐私和援助实施GDPR要求的潜力。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号