首页> 外文会议>Public key infrastructures, services and applications >PorKI: Portable PKI Credentials via Proxy Certificates
【24h】

PorKI: Portable PKI Credentials via Proxy Certificates

机译:PorKI:通过代理证书的便携式PKI凭证

获取原文
获取原文并翻译 | 示例

摘要

Authenticating human users using public key cryptography provides a number of useful security properties, such as being able to authenticate to remote party without giving away a secret. However, in many scenarios, users need to authenticate from a number of client machines, of varying degrees of trustworthiness. In previous work, we proposed an approach to solving this problem by giving users portable devices which wirelessly issue temporary, limited-use proxy certificates to the clients. In this paper, we describe our complete prototype, enabling the use of proxy credentials issued from a mobile device to securely authenticate users to remote servers via a shared (or otherwise not trusted) device. In particular, our PorKI implementation combines out-of-band authentication (via 2D barcode images), standard Proxy Certificates, and platform attestation to provide usable and secure temporary credentials for web-based applications.
机译:使用公共密钥密码对用户进行身份验证可提供许多有用的安全属性,例如能够在不泄露秘密的情况下向远程方进行身份验证。但是,在许多情况下,用户需要从许多不同可信度的客户端计算机上进行身份验证。在先前的工作中,我们提出了一种解决方法,通过为用户提供便携式设备,这些设备可以无线地向客户端颁发临时的,有限使用的代理证书。在本文中,我们描述了完整的原型,使我们能够使用从移动设备发出的代理凭据来通过共享(或其他不受信任的)设备向远程服务器安全地认证用户。特别是,我们的PorKI实现将带外身份验证(通过2D条码图像),标准代理证书和平台证明相结合,从而为基于Web的应用程序提供了可用且安全的临时凭据。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号