首页> 外文会议>Conference on Mobile and Secure Services >Sesame: a secure and convenient mobile solution for passwords
【24h】

Sesame: a secure and convenient mobile solution for passwords

机译:芝麻:安全便捷的密码移动解决方案

获取原文

摘要

Passwords are the main and most common method of remote authentication. However, they have their own frustrating challenges. Users tend to forget passwords that are chosen to be hard to guess. Password managers are an approach to keeping our passwords safe. However, they mainly rely on one master password to secure all of our passwords. If this master password is compromised then all other passwords can be recovered. In this work, we introduce Sesame: a secure yet convenient mobile-based, voice-activated password manager. It combines all different methods of user authentication to create a more robust digital vault for personal data. Each password is encrypted with a new fresh key on the user's mobile device for maximum security. The keys are stored in our servers in a protected format. The user has the option of backing up the encrypted passwords in any cloud service. To view a password, the user only needs to utter the name of a web service, and speaker and speech recognition are applied for authentication. Only the key for that service is sent to the mobile application and the password is decrypted and displayed. The biggest advantage of Sesame is that the user need not assume any trust to neither our servers nor any cloud storage. Also, there is no need to enter a master password every time since speaker recognition is used. However, as an alternative to voice, users can view their passwords using a master password in case voice is not available. We provide a brief analysis of the security of our solution that has been implemented on Android platform and freely available on Google Play. Sesame is an ideal and practical solution for mobile password managers.
机译:密码是远程身份验证的主要和最常见的方法。但是,他们有自己令人沮丧的挑战。用户倾向于忘记难以猜测的密码。密码管理器是一种确保我们的密码安全的方法。但是,它们主要依靠一个主密码来保护我们所有的密码。如果此主密码被盗用,则可以恢复所有其他密码。在这项工作中,我们介绍Sesame:安全,便捷,基于移动设备的语音激活密码管理器。它结合了所有不同的用户身份验证方法,以创建用于个人数据的更强大的数字保险库。每个密码都使用用户移动设备上的新的新密钥加密,以实现最大的安全性。密钥以受保护的格式存储在我们的服务器中。用户可以选择备份任何云服务中的加密密码。要查看密码,用户只需要说出Web服务的名称,然后将说话者和语音识别应用于身份验证。仅将该服务的密钥发送到移动应用程序,然后解密并显示密码。 Sesame的最大优点是,用户无需对我们的服务器或任何云存储都没有任何信任。此外,由于使用了说话人识别功能,因此无需每次都输入主密码。但是,作为语音的替代方法,如果语音不可用,用户可以使用主密码查看其密码。我们对我们的解决方案的安全性进行了简要分析,该解决方案已在Android平台上实现,并在Google Play上免费提供。芝麻是移动密码管理器的理想且实用的解决方案。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号