首页> 外文学位 >Convenient decentralized authentication using passwords.
【24h】

Convenient decentralized authentication using passwords.

机译:使用密码方便的分散式身份验证。

获取原文
获取原文并翻译 | 示例

摘要

Passwords are a very convenient way to authenticate. In terms of simplicity and portability they are very difficult to match. Nevertheless, current password-based login mechanisms are vulnerable to phishing attacks and typically require users to create and manage a new password for each of their accounts. This research investigates the potential for indirect/decentralized approaches to improve password-based authentication. Adoption of a decentralized authentication mechanism requires the agreement between users and service providers on a trusted third party that vouches for users' identities.;Email providers are the de facto trusted third parties on the Internet. Proof of email address ownership is typically required to both create an account and to reset a password when it is forgotten. Despite its shortcomings (e.g., latency, vulnerability to passive attack), this approach is a practical solution to the difficult problem of authenticating strangers on the Internet. This research utilizes this emergent, lightweight relationship with email providers to offload primary user authentication from service providers; thus reducing the need for service provider-specific passwords. Our goal is to provide decentralized authentication that maintains the convenience and portability of passwords, while improving its assurances (especially against phishing).;Our first step to leverage this emergent trust, Simple Authentication for the Web (SAW), improves the security and convenience of email-based authentications and moves them from the background into the forefront, replacing need for an account-specific password. Wireless Authenticationg using Remote Passwords (WARP) adapts the principles of SAW to authentication in wireless networks. Lightweight User AUthentication (Luau) improves upon WARP and unifies user authentication across the application and network (especially wireless) layers. Our final protocol, pwdArmor, started as a simple wrapper to facilitate the use of existing databases of password verifiers in Luau, but grew into a generic middleware framework that augments the assurances of conventional password protocols.;Keywords: authentication, email-based authentication, passwords, password-authenticated key exchange, single sign-on, authentication in wireless networks
机译:密码是一种非常方便的身份验证方法。就简单性和可移植性而言,它们很难匹配。尽管如此,当前基于密码的登录机制很容易受到网络钓鱼攻击,并且通常要求用户为其每个帐户创建和管理新密码。这项研究调查了间接/分散方法来改进基于密码的身份验证的潜力。采用分散式身份验证机制需要用户和服务提供商之间在可信赖的第三方上达成协议,以保证用户的身份。电子邮件提供商是Internet上事实上的可信任的第三方。创建帐户和忘记密码时,通常都需要提供电子邮件地址所有权证明。尽管存在缺点(例如,延迟,易受被动攻击的攻击),但是这种方法是一种实用的解决方案,可以解决在Internet上对陌生人进行身份验证的难题。这项研究利用与电子邮件提供商的这种新兴的,轻量级的关系来减轻服务提供商的主要用户身份验证的负担。这样就减少了对服务提供商特定密码的需求。我们的目标是提供分散的身份验证,以保持密码的便利性和可移植性,同时提高对密码的保证(尤其是防止网络钓鱼)。;我们利用这种新兴信任的第一步,即Web简单身份验证(SAW),可以提高安全性和便利性基于电子邮件的身份验证,并将其从后台移至最前沿,从而无需使用特定于帐户的密码。使用远程密码(WARP)的无线身份验证g使SAW原理适应无线网络中的身份验证。轻量级用户认证(Luau)改进了WARP,并在应用程序和网络(尤其是无线)层之间统一了用户身份验证。我们的最终协议pwdArmor最初是一个简单的包装程序,以方便在Luau中使用密码验证程序的现有数据库,但后来发展成为一个通用的中间件框架,可增强对常规密码协议的保证。关键字:身份验证,基于电子邮件的身份验证,密码,经过密码验证的密钥交换,单点登录,无线网络中的验证

著录项

  • 作者

    van der Horst, Timothy W.;

  • 作者单位

    Brigham Young University.;

  • 授予单位 Brigham Young University.;
  • 学科 Computer Science.
  • 学位 Ph.D.
  • 年度 2010
  • 页码 147 p.
  • 总页数 147
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号