首页> 外文会议>International Conference on Network and System Security >The Mobile Phone as a Multi OTP Device Using Trusted Computing
【24h】

The Mobile Phone as a Multi OTP Device Using Trusted Computing

机译:使用可信计算的移动电话作为多OTP设备

获取原文

摘要

The rapid growth in the number of online services leads to an increasing number of different digital identities each user needs to manage. As a result, many people feel overloaded with credentials, which in turn negatively impacts their abilityto manage them securely. Passwords are perhaps the most common type of credential used today. To avoid the tedious task of remembering difficult passwords, users often behave less securely by using low entropy and weak passwords. Weak passwords and bad password habits represent security threats to online services. Some solutions have been developed to eliminate the need for users to create and manage passwords. A typical solution is based on giving the user a hardware token that generates one-time-passwords, i.e. passwords for single session or transaction usage. Unfortunately, most of these solutions do not satisfy scalability and/or usability requirements, or they are simply insecure. In this paper, we propose a scalable OTP solution using mobile phones and based on trusted computing technology that combines enhanced usability with strong security.
机译:在线服务数量的快速增长导致越来越多的不同数字身份,每个用户需要管理。因此,许多人感到凭证过载,这反过来又对其安全地管理它们的能力产生负面影响。密码可能是今天使用的最常用类型的凭证。为避免记住困难密码的繁琐任务,用户通常通过使用低熵和弱密码来表现得更牢固。密码弱密码和密码习惯代表在线服务的安全威胁。已经开发出一些解决方案来消除用户创建和管理密码的需求。典型的解决方案是基于给用户提供一个硬件令牌,该硬件令牌生成一次性密码,即单个会话或事务使用的密码。遗憾的是,大多数这些解决方案都不满足可扩展性和/或可用性要求,或者它们只是不安全。在本文中,我们使用移动电话提出可扩展的OTP解决方案,并基于可信计算技术,将增强的可用性与强大的安全性相结合。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号