首页> 外文会议>Secyruty standardisation research >Secure Modular Password Authentication for the Web Using Channel Bindings
【24h】

Secure Modular Password Authentication for the Web Using Channel Bindings

机译:使用通道绑定的Web安全模块化密码身份验证

获取原文
获取原文并翻译 | 示例

摘要

Secure protocols for password-based user authentication are well-studied in the cryptographic literature but have failed to see widespread adoption on the Internet; most proposals to date require extensive modifications to the Transport Layer Security (TLS) protocol, making deployment challenging. Recently, a few modular designs have been proposed in which a cryptographically secure password-based mutual authentication protocol is run inside a confidential (but not necessarily authenticated) channel such as TLS; the password protocol is bound to the established channel to prevent active attacks. Such protocols are useful in practice for a variety of reasons: security no longer relies on users' ability to validate server certificates and can potentially be implemented with no modifications to the secure channel protocol library. We provide a systematic study of such authentication protocols. Building on recent advances in modelling TLS, we give a formal definition of the intended security goal, which we call password-authenticated and confidential channel establishment (PACCE). We show generically that combining a secure channel protocol, such as TLS, with a password authentication protocol, where the two protocols are bound together using either the transcript of the secure channel's handshake or the server's certificate, results in a secure PACCE protocol. Our prototype based on TLS is available as a cross-platform client-side Firefox browser extension and a server-side web application which can easily be installed on deployed web browsers and servers.
机译:在密码学文献中已经对基于密码的用户身份验证的安全协议进行了充分研究,但未能在Internet上广泛采用。迄今为止,大多数建议都需要对传输层安全性(TLS)协议进行大量修改,这给部署带来了挑战。最近,有人提出了一些模块化设计,其中在诸如TLS之类的机密(但不一定经过认证)通道内运行基于密码安全的基于密码的相互认证协议。密码协议绑定到已建立的通道,以防止主动攻击。这样的协议在实践中由于多种原因而有用:安全不再依赖于用户验证服务器证书的能力,并且可以在不修改安全通道协议库的情况下实现。我们提供了有关此类身份验证协议的系统研究。基于TLS建模的最新进展,我们给出了预期的安全目标的正式定义,我们将其称为经过密码验证和机密的通道建立(PACCE)。我们大体上表明,将安全通道协议(例如TLS)与密码身份验证协议结合在一起(使用安全通道的握手记录或服务器证书的抄本将这两个协议绑定在一起),就会形成安全的PACCE协议。我们基于TLS的原型可以作为跨平台客户端Firefox浏览器扩展和服务器端Web应用程序使用,可以轻松地将其安装在已部署的Web浏览器和服务器上。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号