首页> 外文期刊>Advances in Science, Technology and Engineering Systems >A Taxonomy for Enhancing Usability, Flexibility, and Security of User Authentication
【24h】

A Taxonomy for Enhancing Usability, Flexibility, and Security of User Authentication

机译:增强可用性,灵活性和用户身份验证安全性的分类法

获取原文
       

摘要

Two technology trends – a move toward software defined capabilities and toward networked devices – support both unprecedented innovations and requirements for security. A fundamental aspect of security is user authentication, which allows devices and software applications to establish their user’s identity and identity is in turn used to establish which of its capabilities the user is authorized to access. While multiple authentication steps, known as multifactor authentication, are being used more widely throughout the military, government, businesses, and consumer sectors, the selection and implementation of which authentication factors to require is typically defined by security policy. Security policy is in turn typically established by a security organization that may have no formal metrics or means to guide its selection of authentication factors. This paper will present a taxonomy for describing authentication factors including important attributes that characterize authentication robustness to aid in the selection of factors that are consistent with the user’s mission. One particular authentication factor that I have developed will be discussed in the context of this taxonomy to motivate the need to broaden current definitions and security policies. The ultimate goal of this paper is to inspire the development of standards for authentication technologies to both support mission aware authentication innovation and to inform decision making about security policies concerning user authentication and authorization. Further, this paper aims to demonstrate that such an approach will fundamentally enhance both security and usability of increasingly networked, software-defined devices, equipment and software applications.
机译:两种技术趋势-向软件定义的功能和向网络设备的过渡-支持空前的创新和对安全性的要求。安全性的一个基本方面是用户身份验证,它允许设备和软件应用程序建立其用户的身份,身份又被用来确定该用户被授权访问其哪些功能。尽管在军事,政府,企业和消费者部门中广泛使用了称为多因素身份验证的多个身份验证步骤,但通常需要通过安全策略来定义对哪些身份验证因素的选择和实现。反过来,安全策略通常由安全组织建立,该组织可能没有正式的度量标准或方法来指导其选择验证因素。本文将提供一种分类法,用于描述认证因素,包括表征认证鲁棒性的重要属性,以帮助选择与用户任务相一致的因素。我将在此分类法的背景下讨论我开发的一种特殊的身份验证因素,以激发对扩展当前定义和安全策略的需求。本文的最终目标是启发身份验证技术标准的发展,以支持任务感知的身份验证创新,并为有关用户身份验证和授权的安全策略决策提供依据。此外,本文旨在证明这种方法将从根本上增强日益联网的软件定义的设备,设备和软件应用程序的安全性和可用性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号