...
首页> 外文期刊>The international arab journal of information technology >UTP: A Novel PIN Number Based User Authentication Scheme
【24h】

UTP: A Novel PIN Number Based User Authentication Scheme

机译:UTP:基于PIN号的用户身份验证方案

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

This paper proposes a Personal Identification Number (PIN) number based authentication scheme named User Transformed PIN (UTP). It introduces a simple cognitive process with which users may transform their PIN numbers into a dynamic one-time number. PIN numbers are widely used for the purpose of user authentication. They are entered directly and reused several times. This makes them vulnerable to many types of attacks. To overcome their drawbacks, One Time Password (OTPs) are combined with PIN numbers to form a stronger two factor authentication. Though it is relatively difficult to attack OTPs, nevertheless OTPs are not foolproof to attacks. In our proposed work, we have devised a new scheme that withstands many of the common attacks on PIN numbers and OTPs. In our scheme, users will generate the UTP with the help of a visual pattern, random alphabets sequence and a PIN number. Because the UTP varies for each transaction, it acts like an OTP. Our scheme conceals PIN number within the UTP so that no direct entry of PIN number is required. The PIN number could be retrieved from the UTP by the authenticator module at the server. To the best our knowledge, this is the first scheme that facilitates users to transform their PIN numbers into a one-time number without any special device or tool. Our scheme is an inherently multi factor authentication by combining knowledge factor and possession factor within itself. The user studies we conducted on the prototype have provided encouraging results to support the scheme's security and usability.
机译:本文提出了基于个人识别码(PIN)基于验证方案的个人识别号码(PIN)名为用户变换的PIN(UTP)的身份验证方案。它介绍了一个简单的认知过程,用户可以将其引脚数转换为动态一次性号码。 PIN编号广泛用于用户身份验证的目的。它们直接输入并重复使用了几次。这使得它们容易受到许多类型的攻击。为了克服他们的缺点,一个时间密码(OTPS)与PIN号组合,以形成更强的两个因子认证。虽然攻击OTPS相对难以攻击OTPS并不是万无一失的攻击。在我们拟议的工作中,我们设计了一种新的计划,可承受着许多常见攻击PIN数和OTPS。在我们的计划中,用户将在视觉模式,随机字母序列和PIN码的帮助下生成UTP。因为UTP因每次交易而异,它就像OTP一样。我们的计划隐藏UTP内的PIN码,以便不需要直接输入PIN码。可以通过服务器的认证器模块从UTP检索引脚数。据我们所知,这是第一个促进用户将其PIN码转换为无任何特殊设备或工具的一次性号码的方案。我们的计划是通过将知识因素和占有因素组合在本身内的本身性因子认证。我们在原型中进行的用户学习已经提供了令人鼓舞的结果,以支持该计划的安全性和可用性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号