首页> 外文期刊>IEICE transactions on information and systems >How to Preserve User Anonymity in Password-Based Anonymous Authentication Scheme
【24h】

How to Preserve User Anonymity in Password-Based Anonymous Authentication Scheme

机译:如何在基于密码的匿名身份验证方案中保留用户匿名

获取原文
       

摘要

A purpose of password-based anonymous authentication schemes is to provide not only password-based authentication but also user anonymity. In [19], Yang et al., proposed a password-based anonymous authentication scheme (we call it YZWB10 scheme) using the password-protected credentials. In this paper, we discuss user anonymity of the YZWB10 scheme [19] against a third-party attacker, who is much weaker than a malicious server. First, we show that a third-party attacker in the YZWB10 scheme can specify which user actually sent the login request to the server. This attack also indicates that the attacker can link different login requests to be sent later by the same user. Second, we give an effective countermeasure to this attack which does not require any security for storing users' password-protected credentials.
机译:基于密码的匿名认证方案的目的是不仅提供基于密码的认证,而且还提供用户匿名性。在[19]中,Yang等人提出了一种使用密码保护的凭据的基于密码的匿名身份验证方案(我们称为YZWB10方案)。在本文中,我们讨论了针对第三方攻击者的YZWB10方案[19]的用户匿名性,该第三方攻击者比恶意服务器弱得多。首先,我们证明YZWB10方案中的第三方攻击者可以指定哪个用户实际向服务器发送了登录请求。该攻击还表明攻击者可以链接不同的登录请求,以稍后由同一用户发送。其次,我们对这种攻击给出了有效的对策,它不需要任何安全性即可存储用户的密码保护凭据。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号