首页> 外文会议>International Workshop on Security Protocols >Raven Authentication Service Attacks and Countermeasures
【24h】

Raven Authentication Service Attacks and Countermeasures

机译:乌鸦认证服务攻击和对策

获取原文

摘要

Raven is the name of the University of Cambridge's central web authentication service. Many online resources within the University require Raven authentication to protect private data. Individual users are uniquely identified by their Common Registration Scheme identifier (CRSid), and protected online resources refer users to the Raven service for verification of a password. We perform a formal analysis of the proprietary Ucam Webauth protocol and identify a number of practical attacks against the Raven service that uses it. Having considered each vulnerability, we discuss the general principles and lessons that can be learnt to help avoid such vulnerabilities in the future.
机译:Raven是剑桥大学的中央Web身份验证服务的名称。大学内的许多在线资源都需要Raven身份验证来保护私人数据。单个用户是唯一的通过常用登记方案标识符(CRSID)识别的,并且受保护的在线资源将用户推荐给RAVEN服务以验证密码。我们对专有的UCAM WebAuth协议进行了正式分析,并识别对使用它的乌鸦服务的许多实际攻击。我们考虑了每个漏洞,我们讨论了可以学习的一般原则和课程,以帮助避免将来避免此类漏洞。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号