首页> 外文期刊>Information Forensics and Security, IEEE Transactions on >oPass: A User Authentication Protocol Resistant to Password Stealing and Password Reuse Attacks
【24h】

oPass: A User Authentication Protocol Resistant to Password Stealing and Password Reuse Attacks

机译:oPass:抵抗密码窃取和密码重用攻击的用户身份验证协议

获取原文
获取原文并翻译 | 示例

摘要

Text password is the most popular form of user authentication on websites due to its convenience and simplicity. However, users' passwords are prone to be stolen and compromised under different threats and vulnerabilities. Firstly, users often select weak passwords and reuse the same passwords across different websites. Routinely reusing passwords causes a domino effect; when an adversary compromises one password, she will exploit it to gain access to more websites. Second, typing passwords into untrusted computers suffers password thief threat. An adversary can launch several password stealing attacks to snatch passwords, such as phishing, keyloggers and malware. In this paper, we design a user authentication protocol named oPass which leverages a user's cellphone and short message service to thwart password stealing and password reuse attacks. oPass only requires each participating website possesses a unique phone number, and involves a telecommunication service provider in registration and recovery phases. Through oPass, users only need to remember a long-term password for login on all websites. After evaluating the oPass prototype, we believe oPass is efficient and affordable compared with the conventional web authentication mechanisms.
机译:文本密码由于其便利性和简单性,是网站上用户身份验证的最流行形式。但是,在不同的威胁和漏洞下,用户的密码容易被窃取和泄露。首先,用户经常选择弱密码,并在不同网站上重复使用相同的密码。定期重用密码会导致多米诺骨牌效应。当对手泄露一个密码时,她将利用该密码来访问更多网站。其次,在不受信任的计算机中输入密码会遭受密码窃贼的威胁。攻击者可以发起多种密码窃取攻击来抢夺密码,例如网络钓鱼,键盘记录程序和恶意软件。在本文中,我们设计了一种名为oPass的用户身份验证协议,该协议利用用户的手机和短消息服务来阻止密码窃取和密码重用攻击。 oPass仅要求每个参与的网站拥有唯一的电话号码,并在注册和恢复阶段让电信服务提供商参与。通过oPass,用户只需要记住一个长期密码即可在所有网站上登录。在评估了oPass原型后,我们认为与传统的Web身份验证机制相比,oPass是高效且价格合理的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号