首页> 外文会议>Proceedings of the 2005 workshop on Digital identity management >Authentication using multiple communication channels
【24h】

Authentication using multiple communication channels

机译:使用多个通讯渠道进行身份验证

获取原文
获取原文并翻译 | 示例

摘要

We discuss an authentication method using multiple communication channels. This method enables on-line service providers to strongly authenticate their users on a non-trusted communication channel (e.g. using a kiosk PC in an Internet cafe to access the Internet) via trusted communication channels (e.g. a mobile phone network). For the illustration purpose, we use a commonly available configuration in the current marketplace, in which users access service providers through PCs over the Internet and also have mobile phones with user identification capabilities (e.g. UIM), throughout the paper. The method uses a unique identifier (e.g. UIM, device ID or a digital certificate) on a mobile phone terminal to authenticate users so that the users do not have to input any person-identifiable information or to install devices and/or software on the non-trusted PCs?for the authentication. The authentication is done in the following manner. (1) A user reads a session-id of a communication channel between a service provider and a PC using a barcode reader on a mobile phone terminal and (2) sends the session-id through mutual authenticated secure channel over a mobile phone network to the authentication server and (3) the authentication server matches the session-id and binds the user with the corresponding communication channel to provide service to the PC.Our method can also prevent users to be "phished" by double checking the returned authenticator from the service provider.
机译:我们讨论使用多个通信通道的身份验证方法。该方法使在线服务提供商能够经由受信任的通信信道(例如,移动电话网络)在非受信任的通信信道上(例如,使用网吧中的售货亭PC访问互联网)对他们的用户进行强力认证。为了说明的目的,我们在当前市场中使用一种普遍可用的配置,其中用户通过Internet上的PC通过PC访问服务提供商,并且在整篇文章中还拥有具有用户识别功能的手机(例如UIM)。该方法使用移动电话终端上的唯一标识符(例如,UIM,设备ID或数字证书)来对用户进行身份验证,以便用户不必输入任何可识别个人的信息或在非移动设备上安装设备和/或软件。受信任的PC进行身份验证。认证以以下方式进行。 (1)用户使用手机终端上的条形码读取器读取服务提供商和PC之间的通信通道的会话ID,然后(2)通过相互认证的安全通道,通过手机网络将会话ID发送到身份验证服务器和(3)身份验证服务器匹配会话ID,并将用户与相应的通信通道绑定,以向PC提供服务。我们的方法还可以通过再次检查从服务器返回的身份验证器来防止用户被“欺骗”。服务提供者。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号