首页> 外文期刊>Journal of computer security >WebCallerID: Leveraging cellular networks for Web authentication
【24h】

WebCallerID: Leveraging cellular networks for Web authentication

机译:WebCallerID:利用蜂窝网络进行Web身份验证

获取原文
获取原文并翻译 | 示例
           

摘要

Web authentication that is both secure and usable remains a challenge. Passwords are vulnerable to phishing attacks, while physical tokens face deployment obstacles. We propose to leverage the authentication infrastructure of cellular networks to enhance Web authentication. We design WebCallerlD, a Web authentication scheme that uses cell phones as physical tokens and uses cellular networks as trusted identity providers. Since WebCallerlD requires no user participation during authentication, it prevents security mistakes by users. WebCallerlD also prevents rogue websites from replaying authentication assertions or stealing users' identities. We have implemented a prototype of WebCallerlD using the OpenID framework. The prototype shows that WebCallerlD seamlessly integrates into OpenlD-capable Web authentication while avoiding phishing problems in OpenID and simplifying user participation.
机译:安全且可用的Web身份验证仍然是一个挑战。密码容易受到网络钓鱼攻击,而物理令牌面临部署障碍。我们建议利用蜂窝网络的身份验证基础结构来增强Web身份验证。我们设计WebCallerID,这是一种Web身份验证方案,它使用手机作为物理令牌,并使用蜂窝网络作为受信任的身份提供者。由于WebCallerID在身份验证期间不需要用户参与,因此可以防止用户的安全错误。 WebCallerID还可以防止恶意网站重播身份验证声明或窃取用户身份。我们已经使用OpenID框架实现了WebCallerID的原型。原型表明,WebCallerID无缝集成到支持OpenID的Web身份验证中,同时避免了OpenID中的网络钓鱼问题并简化了用户参与。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号