首页> 外文期刊>IEEE transactions on mobile computing >PROTECT: Efficient Password-Based Threshold Single-Sign-On Authentication for Mobile Users against Perpetual Leakage
【24h】

PROTECT: Efficient Password-Based Threshold Single-Sign-On Authentication for Mobile Users against Perpetual Leakage

机译:保护:基于基于密码的基于密码的阈值单点登录身份验证,用于移动用户免受永久泄漏

获取原文
获取原文并翻译 | 示例

摘要

Password-based single-sign-on authentication has been widely applied in mobile environments. It enables an identity server to issue authentication tokens to mobile users holding correct passwords. With an authentication token, one can request mobile services from related service providers without multiple registrations. However, if an adversary compromises the identity server, he can retrieve users' passwords by performing dictionary guessing attacks (DGA) and can overissue authentication tokens to break the security. In this paper, we propose a password-based threshold single-sign-on authentication scheme dubbed PROTECT that thwarts adversaries who can compromise identity server(s), where multiple identity servers are introduced to authenticate mobile users and issue authentication tokens in a threshold way. PROTECT supports key renewal that periodically updates the secret on each identity server to resist perpetual leakage of the secret. Furthermore, PROTECT is secure against off-line DGA: a credential used to authenticate a user is computed from the password and a server-side key. PROTECT is also resistant to online DGA and password testing attacks in an efficient way. We conduct a comprehensive performance evaluation of PROTECT, which demonstrates the high efficiency on the user side in terms of computation and communication and proves that it can be easily deployed on mobile devices.
机译:基于密码的单点登录身份验证已广泛应用于移动环境。它使身份服务器能够向持有正确密码的移动用户发出身份验证令牌。使用身份验证令牌,可以从未提供多个注册的相关服务提供商请求移动服务。但是,如果对手妥协了身份服务器,他可以通过执行字典猜测攻击(DGA)来检索用户的密码,并且可以过度验证令牌来打破安全性。在本文中,我们提出了一种基于密码的阈值单签到的身份验证方案被称为阻止可能危及身份服务器的对手,其中引入多个身份服务器以验证移动用户并以阈值方式发出身份验证令牌的影响。保护支持关键更新,定期更新每个身份服务器上的秘密以抵制秘密的永久泄漏。此外,保护对离线DGA的保护是安全的:从密码和服务器端键计算用于验证用户的凭证。保护也以有效的方式对在线DGA和密码测试攻击抵抗。我们进行了全面的绩效评估,这在计算和通信方面展示了用户方面的高效率,并证明它可以很容易地部署在移动设备上。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号