首页> 外文期刊>Journal of computer security >Leveraging personal devices for stronger password authentication from untrusted computers
【24h】

Leveraging personal devices for stronger password authentication from untrusted computers

机译:利用个人设备从不受信任的计算机获得更强的密码身份验证

获取原文
获取原文并翻译 | 示例
       

摘要

Internet authentication for popular end-user transactions, such as online banking and e-commerce, continues to be dominated by passwords entered through end-user PCs. Most users continue to prefer (typically untrusted) PCs over smaller personal devices for actual transactions, due to usability features related to keyboard and screen size. However, most such transactions and their underlying protocols are vulnerable to attacks including keylogging, phishing and pharming. We propose Mobile Password Authentication (MP-Auth) to counter such attacks, which cryptographically separates a user's long-term secret input from the client PC, and offers transaction integrity. The PC continues to be used for most of the interaction but has access only to temporary secrets, while the user's long-term secret is input through an independent personal device, e.g., a cellphone which makes it available to the PC only after encryption under the intended far-end recipient's public key. MP-Auth expects users to input passwords only to a personal device, and be vigilant while confirming transactions from the device. To facilitate a comparison to MP-Auth, we also provide a comprehensive survey of web authentication techniques that use an additional factor of authentication; this survey may be of independent interest.
机译:互联网用户对流行的最终用户交易(例如,在线银行和电子商务)的身份验证仍主要由通过最终用户PC输入的密码来控制。由于与键盘和屏幕尺寸有关的可用性功能,大多数用户在较小的个人设备上仍然喜欢使用PC(通常是不受信任的PC)来进行实际交易。但是,大多数此类交易及其底层协议都容易受到攻击,包括键盘记录,网络钓鱼和欺骗。我们建议使用移动密码身份验证(MP-Auth)来应对此类攻击,该攻击通过密码将用户的长期秘密输入与客户端PC分开,并提供交易完整性。 PC继续用于大多数交互,但只能访问临时机密,而用户的长期机密则是通过独立的个人设备(例如手机)输入的,该个人设备只有在经过加密后才可用于PC。预期的远端收件人的公钥。 MP-Auth希望用户仅将密码输入到个人设备,并在确认来自该设备的交易时保持警惕。为了便于与MP-Auth进行比较,我们还提供了对Web身份验证技术的全面调查,其中使用了其他身份验证因素。此调查可能具有独立利益。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号