首页> 外文会议>Computer Security Applications Conference >An Intrusion-Tolerant Password Authentication System
【24h】

An Intrusion-Tolerant Password Authentication System

机译:一种可侵于容忍的密码认证系统

获取原文

摘要

In a password-based authentication system, to authenticate a user, a server typically stores password verification data (PVD), which is a value derived from the user's password using publicly known functions. For those users whose passwords fall within an attacker's dictionary, their PVDs, if stolen (for example, through server compromise), will allow the attacker to mount off-line dictionary attacks. In this article, we describe a password authentication system that can tolerate server compromises. The described system uses multiple (say n) servers to share password verification data and never reconstructs the shared PVD during user authentications. Only a threshold number (say t, t ≤ n) of these servers are required for a user authentication and compromising up to (t - 1) of these servers will not allow an attacker to mount off-line dictionary attacks, even if a user's password falls within the attacker's dictionary. The described system can still function if some of the servers are unavailable. In this paper, we give the system architecture and implementation details. Our experimental results show that the described system works well. The given system can be used to build intrusion-tolerant applications.
机译:在基于密码的身份验证系统中,用于验证用户,服务器通常存储密码验证数据(PVD),这是使用公知的功能从用户密码导出的值。对于那些密码落在攻击者字典中的用户,如果被盗(例如,通过服务器妥协),它们的PVD将允许攻击者挂载离线词典攻击。在本文中,我们描述了一个可以容忍服务器妥协的密码身份验证系统。所描述的系统使用多个(例如n)服务器来共享密码验证数据,并且永远不会在用户身份认证期间重建共享的PVD。用户身份验证只需要这些服务器的阈值(例如T,T≤N),并且即使用户的用户也不允许攻击者将不允许攻击者安装在线词典攻击。密码落在攻击者的字典内。如果某些服务器不可用,所描述的系统仍可运行。在本文中,我们提供系统架构和实现细节。我们的实验结果表明,所述系统运行良好。给定的系统可用于构建可侵于容忍应用程序。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号