...
首页> 外文期刊>Security & Privacy, IEEE >When the Password Doesn't Work: Secondary Authentication for Websites
【24h】

When the Password Doesn't Work: Secondary Authentication for Websites

机译:密码不起作用时:网站的二次身份验证

获取原文
获取原文并翻译 | 示例

摘要

Nearly all websites today use passwords as the primary means of authenticating users. Because passwords can be lost or stolen, most websites also provide secondary authentication: a means to allow users unable to provide the correct password to regain access to their accounts. The consequences of failure - either falsely rejecting the account owner or falsely accepting an impostor - are significant. If the secondary authentication mechanism is the user's last resort, a false reject can mean permanent account loss. If the mechanism's vulnerability to false accepts isn't as strong as that of passwords, the secondary authentication mechanism becomes the weakest link and limits account's security. The authors highlight results of prior work on secondary authentication mechanisms, emphasizing the larger problem of assembling an arsenal of mechanisms that can be customized to fit each user's security and reliability needs.
机译:如今,几乎所有网站都使用密码作为验证用户身份的主要手段。由于密码可能会丢失或被盗,因此大多数网站还提供了二级身份验证:一种允许用户无法提供正确密码来重新获得其帐户访问权限的方法。失败的后果-错误地拒绝帐户所有者或错误地接受冒名顶替者-都是重大的。如果辅助身份验证机制是用户的最后选择,则错误的拒绝会导致永久帐户丢失。如果该机制对错误接受的脆弱性不如密码脆弱,则辅助身份验证机制将成为最弱的链接,并限制帐户的安全性。作者着重介绍了先前在二级身份验证机制上的工作成果,强调了更大的问题是组装可定制的机制以适应每个用户的安全性和可靠性需求。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号