...
首页> 外文期刊>Computers & Security >Toward a secure and usable cloud-based password manager for web browsers
【24h】

Toward a secure and usable cloud-based password manager for web browsers

机译:面向Web浏览器的安全且可用的基于云的密码管理器

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

Web users are confronted with the daunting challenges of creating, remembering, and using more and more strong passwords than ever before in order to protect their valuable assets on different websites. Password manager, particularly Browser-based Password Manager (BPM), is one of the most popular approaches designed to address these challenges by saving users' passwords and later automatically filling the login forms on behalf of users. Fortunately, all the five most popular Web browsers have provided password managers as a useful built-in feature. In this paper, we uncover the vulnerabilities of existing BPMs and analyze how they can be exploited by attackers to crack users' saved passwords. Moreover, we propose a novel Cloud-based Storage-Free BPM (CSF-BPM) design to achieve a high level of security with the desired confidentiality, integrity, and availability properties. We have implemented a CSF-BPM system into Firefox and evaluated its correctness, performance, and usability. Our evaluation results and analysis demonstrate that CSF-BPM can be efficiently and conveniently used. We believe CSF-BPM is a rational design that can also be integrated into other popular browsers to make the online experience of Web users more secure, convenient, and enjoyable.
机译:为了保护他们在不同网站上的宝贵资产,Web用户面临着创建,记住和使用越来越多的强密码这一艰巨的挑战。密码管理器,特别是基于浏览器的密码管理器(BPM),是最流行的方法之一,旨在通过保存用户密码并随后代表用户自动填写登录表单来解决这些挑战。幸运的是,所有五个最流行的Web浏览器都提供了密码管理器作为有用的内置功能。在本文中,我们发现了现有BPM的漏洞,并分析了攻击者如何利用它们来破解用户保存的密码。此外,我们提出了一种新颖的基于云的无存储BPM(CSF-BPM)设计,以实现具有所需机密性,完整性和可用性属性的高级别安全性。我们已经在Firefox中实现了CSF-BPM系统,并评估了其正确性,性能和可用性。我们的评估结果和分析表明,CSF-BPM可以高效便捷地使用。我们认为CSF-BPM是一种合理的设计,也可以集成到其他流行的浏览器中,以使Web用户的在线体验更加安全,便捷和愉悦。

著录项

  • 来源
    《Computers & Security》 |2014年第10期|32-47|共16页
  • 作者

    Rui Zhao; Chuan Yue;

  • 作者单位

    Department of Computer Science, University of Colorado Colorado Springs, 80918, USA;

    Department of Computer Science, University of Colorado Colorado Springs, 80918, USA;

  • 收录信息 美国《科学引文索引》(SCI);美国《工程索引》(EI);
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    Web browser; Password manager; User authentication; Security; Cloud; Storage;

    机译:网页浏览器;密码管理器;用户认证;安全;云;存储;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号