【24h】

PorKI: Portable PKI Credentials via Proxy Certificates

机译:Porki:通过代理证书的便携式PKI凭据

获取原文

摘要

Authenticating human users using public key cryptography provides a number of useful security properties, such as being able to authenticate to remote party without giving away a secret. However, in many scenarios, users need to authenticate from a number of client machines, of varying degrees of trustworthiness. In previous work, we proposed an approach to solving this problem by giving users portable devices which wirelessly issue temporary, limited-use proxy certificates to the clients. In this paper, we describe our complete prototype, enabling the use of proxy credentials issued from a mobile device to securely authenticate users to remote servers via a shared (or otherwise not trusted) device. In particular, our PorKI implementation combines out-of-band authentication (via 2D barcode images), standard Proxy Certificates, and platform attestation to provide usable and secure temporary credentials for web-based applications.
机译:使用公钥加密进行身份验证人员提供了许多有用的安全性属性,例如能够在不赠送秘密的情况下对远程方进行身份验证。但是,在许多方案中,用户需要从许多客户机,不同程度的可信度进行身份验证。在以前的工作中,我们提出了一种通过为用户提供无线发出临时的有限使用代理证书来解决此问题的方法。在本文中,我们描述了我们的完整原型,使得能够使用从移动设备发出的代理凭据,通过共享(或其他不可信任)设备安全地将用户身到远程服务器。特别是,我们的PORKI实现结合了带外认证(通过2D条形码图像),标准代理证书和平台证明,以为基于Web的应用程序提供可用和安全的临时凭据。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号