【24h】

Seed-based authentication

机译:基于种子的身份验证

获取原文

摘要

Although web user authentication via username/password is widely used, this approach has many drawbacks. For example, users have to memorize textual passwords and to change the passwords frequently. Most importantly many users save their passwords in plain text that can potentially be exploited later. In this paper we proposed a new method for web applications to enhance user authentication that is less dependent on end users' memory. This new method incorporates Pseudo Random Numbers that are generated by a seed stemmed from a root file, such as an image file, managed by the user and shared with the authentication server. The Pseudo Random Numbers, generated upon user login, are then served as one-time passwords for server authentication. We described our design, implementation and experiments that tested the randomness of these one-time passwords in a real world scenario. We also discussed how the proposed scheme can withstand common attacks such as replay attacks, dictionary attacks, and the denial-of-service attacks.
机译:尽管通过用户名/密码进行Web用户身份验证已被广泛使用,但是此方法有许多缺点。例如,用户必须记住文本密码并经常更改密码。最重要的是,许多用户将其密码保存为纯文本格式,以后可能会被利用。在本文中,我们提出了一种用于Web应用程序的新方法来增强用户身份验证,该方法较少依赖最终用户的内存。此新方法合并了伪随机数,这些伪随机数由源于根文件(例如图像文件)的种子生成,该种子由用户管理并与身份验证服务器共享。用户登录时生成的伪随机数将用作服务器身份验证的一次性密码。我们描述了我们的设计,实现和实验,这些实验在实际情况下测试了这些一次性密码的随机性。我们还讨论了所提出的方案如何抵抗常见的攻击,例如重播攻击,字典攻击和拒绝服务攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号