首页> 外文会议>International Conference on Mobile and Secure Services >Stronger authentication for password credential Internet Services
【24h】

Stronger authentication for password credential Internet Services

机译:密码凭据Internet服务更强大的身份验证

获取原文

摘要

Most Web and other on-line service providers (“Internet Services”) only support legacy ID (or email) and password (ID/PW) credential authentication. However, there are numerous vulnerabilities concerning ID/PW credentials. Scholars and the industry have proposed several improved security solutions, such as MFA, however most of the Internet Services have refused to adopt these solutions. Mobile phones are much more sensitive to these vulnerabilities (so this paper focuses on mobile phones). Many users take advantage of password managers, to keep track of all their Internet Service profiles. However, the Internet Service profiles found in password managers, are normally kept on the PC or mobile phone's disk, in an encrypted form. Our first contribution is a design guideline, whereby the Internet Service profiles never need to touch the client's disk. Most users would benefit, if they had the ability to use MFA, to login to a legacy Internet Service, which only supports ID/PW credential authentication. Our second contribution is a design guideline, whereby users can choose, for each legacy ID/PW Internet Service, which specific MFA they wish to use. We have also presenting conceptual design guidelines, showing that both of our contributions are minor changes to existing password managers, which can be implemented easily with low overhead.
机译:大多数Web和其他在线服务提供商(“Internet Services”)仅支持旧版ID(或电子邮件)和密码(ID / PW)凭据身份验证。但是,有许多关于ID / PW凭证的漏洞。学者和行业提出了几种改进的安全解决方案,如MFA,但大多数互联网服务都拒绝采用这些解决方案。移动电话对这些漏洞更敏感(因此本文重点介绍了移动电话)。许多用户利用密码管理器,以跟踪其所有Internet服务配置文件。但是,密码管理器中的Internet服务配置文件通常以加密的表单保持在PC或移动电话的磁盘上。我们的第一款贡献是一种设计指南,由此互联网服务配置文件永远不需要触摸客户端的磁盘。大多数用户将受益,如果他们有能力使用MFA,请登录遗留Internet服务,只支持ID / PW凭证身份验证。我们的第二款贡献是一个设计指南,即用户可以为每个旧版ID / PW Internet服务选择,他们希望使用哪种特定的MFA。我们还提出了概念设计指南,显示我们的两个贡献都是对现有密码管理器的微小更改,可以轻松实现低开销。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号