首页> 外文会议>European Symposium on Research in Computer Security >Scalable Two-Factor Authentication Using Historical Data
【24h】

Scalable Two-Factor Authentication Using Historical Data

机译:使用历史数据可扩展的双因素身份验证

获取原文

摘要

Two-factor authentication is increasingly demanded in the Internet of Things (IoT), especially those deployed in the critical infrastructure. However, resource and operational constraints of typical IoT devices are the key impediment, especially when the IoT device acts as a verifier. This paper proposes a novel authentication factor (namely, historical data) which, when combined with the conventional first authentication factor (a secret key), results in a scalable, lightweight two-factor entity authentication protocol for use in the IoT. In the new authentication factor, the data exchanged between a verifier and a prover is used as the secret information for the verifier to prove his identity to the verifier. Practically, the verifier needs all the historical data to prove his identity. Yet, through an innovative use of the proof of retrievability, the verifier only needs a constant storage regardless of the size of the historical data. Leveraging on the data retrieval and searching capability of contemporary big data technologies, the proposed authentication factor can achieve realtime, fault-tolerant verification. The use of historical data as an authentication factor has a very interesting leakage-resilience property. Besides, the proposed scheme demonstrates a tradeoff between security and computational overhead, and such scalability particularly suits the IoT, with devices of diverse capabilities.
机译:在物联网(物联网)中越来越多地要求双因素认证,尤其是部署在关键基础架构中的因特网。然而,典型物联网设备的资源和操作约束是关键障碍,尤其是当物联网设备充当验证者时。本文提出了一种新颖的认证因素(即历史数据),当与传统的第一认证因子(秘密密钥)组合时,导致可扩展,轻量级的双因子实体认证协议,用于IOT。在新的认证因素中,在验证者和谚语之间交换的数据用作验证者将其身份证明对验证者的秘密信息。实际上,验证者需要所有历史数据来证明他的身份。然而,通过创新使用可检索性证明,无论历史数据的大小如何,验证器只需要恒定的存储。利用当代大数据技术的数据检索和搜索能力,所提出的认证因素可以实现实时,容错验证。使用历史数据作为认证因素具有非常有趣的泄漏弹性属性。此外,所提出的方案展示了安全性和计算开销之间的权衡,以及这种可扩展性特别适合IOT,具有各种能力的设备。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号