【24h】

Pseudo-randomness Inside Web Browsers

机译:Web浏览器内的伪随机性

获取原文

摘要

With the increasing concerns over the security and privacy of Web based applications, many solutions based on strong cryptography have been proposed to protect client side Web applications against attacks such as phishing, pharming and even server side attacks. While strong cryptography is used, one critical building block in cryptosystem, the random number generator, is often neglected. Considering this situation, in this paper we design and implement a pseudo-random number generator only rely on ubiquitous Web browser abilities - JavaScript, HTML and AJAX. We also provide a mechanism called Pseudo-cookie for JavaScript programs to access operating system services for retrieving random or entropy values without changing Web browser security policies. The security model, analysis and performance evaluation demonstrate that our method is secure and efficient.
机译:随着对基于Web的应用程序安全和隐私的越来越多,已经提出了许多基于强密加密的解决方案,以保护客户端Web应用程序免受网络钓鱼,药房甚至服务器侧攻击等攻击。虽然使用了强大的加密,但通常忽略了一个密钥系统,随机数发生器的一个关键构建块。考虑到这种情况,在本文中,我们设计并实现了伪随机数发生器,仅依赖于普遍存在的Web浏览器 - JavaScript,HTML和AJAX。我们还提供了一种称为伪cookie的机制,用于JavaScript程序,用于访问操作系统服务,以检索随机或熵值而不更改Web浏览器安全策略。安全模型,分析和性能评估表明我们的方法是安全和有效的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号