...
首页> 外文期刊>Information security journal:A global perspective >Cookie-Based Virtual Password Authentication Protocol
【24h】

Cookie-Based Virtual Password Authentication Protocol

机译:基于Cookie的虚拟密码身份验证协议

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

The password is the most common technique used to authen ticate Web users. Password-based authentication protocols are susceptible to automated dictionary attacks because most passwords are chosen by users from their personal domain. In this paper, we propose a cookie-based virtual pass word authentication protocol that preserves the advantages of conventional password authentication while simultaneously increasing the efforts required for online dictionary attacks. The Web server stores the cookie on the user's machine if the legitimate user authenticates to the Web server. Thereafter, the legitimate user can easily authenticate to the Web server from a machine that contains the cookie. However, the legitimate user requires some additional computational efforts during login from a machine that does not contain the cookie. The computation efforts required from the attacker during login to the Web server increases exponentially with each login failure. The user generated virtual password is different for the same user in different sessions of Secure Socket Layer (SSL) protocol. The concept used in this paper is to combine traditional password authentication with a challenge that is easy to answer by the legitimate user but computational cost increases for the attacker with each login failure. Therefore, even the automated programs cannot launch online dictionary attacks on the proposed protocol. This protocol provides good secu rity against different types of attacks launched by the attacker. The proposed protocol is easy to implement and removes some of the drawbacks of earlier proposed password-based authentication protocols.
机译:密码是用于认证Web用户的最常用技术。基于密码的身份验证协议容易受到自动词典攻击,因为大多数密码是由用户从其个人域中选择的。在本文中,我们提出了一种基于cookie的虚拟密码身份验证协议,该协议保留了常规密码身份验证的优势,同时又增加了在线词典攻击所需的工作量。如果合法用户对Web服务器进行身份验证,则Web服务器会将cookie存储在用户的计算机上。之后,合法用户可以轻松地从包含cookie的计算机向Web服务器进行身份验证。但是,合法用户在从不包含Cookie的计算机登录时需要进行一些额外的计算工作。每次登录失败时,攻击者在登录到Web服务器时所需的计算量都会成倍增加。在安全套接字层(SSL)协议的不同会话中,同一用户的用户生成的虚拟密码是不同的。本文使用的概念是将传统的密码身份验证与合法用户易于回答的挑战相结合,但每次登录失败都会使攻击者的计算成本增加。因此,即使是自动程序也无法对建议的协议发起在线字典攻击。该协议为攻击者发起的不同类型的攻击提供了良好的安全性。所提出的协议易于实现,并且消除了较早提出的基于密码的身份验证协议的一些缺点。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号