首页> 外文会议>European Workshop on Security in Ad-hoc and Sensor Networks >Securely Propagating Authentication in an Ensemble of Personal Devices Using Single Sign-on
【24h】

Securely Propagating Authentication in an Ensemble of Personal Devices Using Single Sign-on

机译:使用单点登录安全地在个人设备的集合中传播身份验证

获取原文

摘要

More and more, people will continuously be using ubiquitously available networked computational devices as they go about their lives: small personal devices that they carry, appliances that they find in their surroundings, and servers in remote data centers. Some of the data exchanged by these devices will be private and should be protected. Normally to protect data, users would need to authenticate themselves with a device by signing on to it. However it will be physically impossible to sign onto devices that have limited or no user interface and even if they all had a sufficient user interface it will be an intolerable burden to have to sign on to each of many devices, particularly as the membership of the ensemble of devices continuously changes with the user's movements. Making authentication in this environment more difficult is the fact that these devices are usually connected in a personal area network that is neither secure nor reliable and uses a broadcast medium for communication. In this paper, we present a simple easy-to-use scheme that allows users to sign on to a single device and enable the rest of the devices connected in the personal area network automatically without requiring a central server or synchronized clocks. As well as being simple for the user, our solution is designed not only to prevent commonly used attacks like replay and man-in-the-middle but also to protect the user's data even if the devices are lost or stolen.
机译:越来越多地,人们将不断使用普遍存在的网络计算设备,因为他们的生活:他们携带的小型个人设备,他们在周围环境中找到的设备,以及远程数据中心的服务器。这些设备交换的一些数据将是私有的,应该受到保护。通常要保护数据,用户需要通过签名将自己与设备进行身份验证。然而,它将是物理上不可能签署有限或没有用户界面的设备,即使它们都有足够的用户界面,它将是必须登录许多设备中的每一个的无法忍受的负担,特别是作为成员资格设备的集合与用户的动作连续变化。在这种环境中进行认证更困难的是这些设备通常在既安全也不可靠地连接的个人区域网络中,并且使用广播介质进行通信。在本文中,我们介绍了一个简单的易于使用方案,允许用户登录单个设备,并在不需要中央服务器或同步时钟的情况下自动登录单个设备并使其余设备自动连接在个人区域网络中。除了用户简单,我们的解决方案不仅要防止常用的攻击,如重播和中间的攻击,也可以保护用户的数据,即使设备丢失或被盗。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号