首页> 外文期刊>Mobile Networks and Applications >Ubiquitous One-Time Password Service Using the Generic Authentication Architecture
【24h】

Ubiquitous One-Time Password Service Using the Generic Authentication Architecture

机译:使用通用身份验证体系结构的无处不在的一次性密码服务

获取原文
获取原文并翻译 | 示例
       

摘要

The Generic Authentication Architecture (GAA) is a standardised extension to the mobile authentication infrastructure that enables the provision of security services, such as key establishment, to network applications. In this paper we first show how Trusted Computing can be extended in a GAA-like framework to offer new security services. We then propose a general scheme that converts a simple static password authentication mechanism into a one-time password (OTP) system using the GAA key establishment service. The scheme employs a GAA-enabled user device and a GAA-aware server. Most importantly, unlike most OTP systems using a dedicated key-bearing token, the user device does not need to be user or server specific, and can be used in the protocol with no registration or configuration (except for the installation of the necessary application software). We also give two practical instantiations of the general scheme, building firstly on the mobile authentication infrastructure and secondly on Trusted Computing. The practical systems are secure, scalable, fit well to the multi-institution scenario, and enable the provision of ubiquitous and on-demand OTP services.
机译:通用身份验证体系结构(GAA)是对移动身份验证基础结构的标准化扩展,它使向网络应用程序提供安全服务(例如密钥建立)成为可能。在本文中,我们首先展示如何在类似GAA的框架中扩展可信计算,以提供新的安全服务。然后,我们提出一种通用方案,该方案使用GAA密钥建立服务将简单的静态密码身份验证机制转换为一次性密码(OTP)系统。该方案使用支持GAA的用户设备和支持GAA的服务器。最重要的是,与大多数使用专用密钥承载令牌的OTP系统不同,该用户设备不需要特定于用户或服务器,并且可以在协议中使用而无需注册或配置(除了安装必需的应用程序软件外) )。我们还给出了通用方案的两个实际实例,首先是基于移动身份验证基础结构,其次是基于可信计算。实用的系统是安全的,可伸缩的,非常适合多机构方案,并能够提供无处不在的按需OTP服务。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号