...
首页> 外文期刊>Journal of Zhejiang University >Multiple hashes of single key with passcode for multiple accounts
【24h】

Multiple hashes of single key with passcode for multiple accounts

机译:具有多个帐户密码的单个密钥的多个哈希

获取原文
获取原文并翻译 | 示例
           

摘要

A human's e-life needs multiple offline and online accounts. It is a balance between usability and security to set keys or passwords for these multiple accounts. Password reuse has to be avoided due to the domino effect of malicious administrators and crackers. However, human memorability constrains the number of keys. Single sign-on server, key hashing, key strengthening and petname system are used in the prior arts to use only one key for multiple online accounts. The unique site keys are derived from the common master secret and specific domain name. These methods cannot be applied to offline accounts such as file encryption. We invent a new method and system applicable to offline and online accounts. It does not depend on HTTP server and domain name, but numeric 4-digit passcode, key hashing, key strengthening and hash truncation. Domain name is only needed to resist spoofing and phishing attacks of online accounts.
机译:一个人的电子生活需要多个离线和在线帐户。为这些多个帐户设置密钥或密码在可用性和安全性之间取得平衡。由于恶意管理员和破解者的多米诺骨牌效应,必须避免密码重用。但是,人类的记忆力限制了键的数量。在现有技术中,单点登录服务器,密钥散列,密钥加强和小名系统被用于仅将一个密钥用于多个在线帐户。唯一站点密钥派生自公用主密钥和特定域名。这些方法不能应用于脱机帐户,例如文件加密。我们发明了适用于离线和在线帐户的新方法和系统。它不依赖于HTTP服务器和域名,而是依赖于4位数字密码,密钥哈希,密钥加强和哈希截断。仅需要域名才能抵御在线帐户的欺骗和网络钓鱼攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号