首页> 外文会议>IEEE Region 10 Conference >A cloud authentication protocol using One-Time Pad
【24h】

A cloud authentication protocol using One-Time Pad

机译:使用一次性垫的云认证协议

获取原文

摘要

There is a significant increase in the amount of data breaches in corporate servers in the cloud environments. This includes username and password compromise in the cloud and account hijacking, thus leading to severe vulnerabilities of the cloud service provisioning. Traditional authentication schemes rely on the users to use their credentials to gain access to cloud service. However once the credential is compromised, the attacker will gain access to the cloud service easily. This paper proposes a novel scheme that does not require the user to present his credentials, and yet is able to prove ownership of access to the cloud service using a variant of zero-knowledge proof. A challenge-response protocol is devised to authenticate the user, requiring the user to compute a one-time pad (OTP) to authenticate himself to the server without revealing password to the server. A prototype has been implemented to facilitate the authentication of the user when accessing Dropbox, and the experiment results showed that the overhead incurred is insignificant.
机译:云环境中公司服务器中的数据泄露数量显着增加。这包括云中用户名和密码的泄露以及帐户劫持,从而导致云服务供应的严重漏洞。传统的身份验证方案依赖用户使用其凭据来访问云服务。但是,一旦凭据遭到破坏,攻击者将轻松获得对云服务的访问。本文提出了一种新颖的方案,该方案不需要用户提供其凭据,但能够使用零知识证明的变体来证明对云服务的访问所有权。设计了一种质询-响应协议来对用户进行身份验证,要求用户计算一次性密码(OTP)以向服务器进行身份验证,而无需向服务器透露密码。已经实现了原型,以方便在访问Dropbox时对用户进行身份验证,并且实验结果表明所产生的开销微不足道。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号