首页> 外文期刊>Computers in Industry >VOAuth: A solution to protect OAuth against phishing
【24h】

VOAuth: A solution to protect OAuth against phishing

机译:VOAuth:一种保护OAuth免受网络钓鱼的解决方案

获取原文
获取原文并翻译 | 示例
       

摘要

The OAuth protocol is designed for authorization which enables users to grant third-party applications to access their resources stored at a server. However, OAuth cannot prevent counterfeiting the Authorization Server, thus phishing attacks are usually encountered. Although the version 2.0 of OAuth has been widely used in web authorization services, counterfeiting problem remains unsolved. In this paper, VOAuth (Validation OAuth) is proposed as a novel solution to address this problem, which brings in a Validation System and optimizes the processes of OAuth. The Validation System including Validation Gateway and Validation Client can guarantee the authenticity of Authorization Server by taking tripartite consultation and one-time pad into account, hence users can be protected from phishing due to that passwords will not be stored or submitted for a long time. In order to prove that VOAuth can avoid phishing attacks especially counterfeiting Authorization Server effectively, countermeasures on phishing threat models and formal verification in VOAuth are shown with Alloy Analyzer. Finally, VOAuth is implemented in an actual mobile Internet application and has been on-line for more than two years with over 15 million users. So far, the leakage of user privacy data does not occur and there is no phished account reported, which provides further evidence of the effectiveness of VOAuth. (C) 2016 Published by Elsevier B.V.
机译:OAuth协议专为授权而设计,该协议使用户能够授予第三方应用程序访问其存储在服务器上的资源。但是,OAuth无法阻止伪造授权服务器,因此通常会遇到网络钓鱼攻击。尽管OAuth 2.0版已广泛用于Web授权服务,但伪造问题仍未解决。在本文中,提出了VOAuth(验证OAuth)作为解决此问题的新方法,它引入了验证系统并优化了OAuth的流程。包括验证网关和验证客户端的验证系统可以通过考虑三方协商和一次性授权来保证授权服务器的真实性,因此可以保护用户免受网络钓鱼的侵害,因为密码不会被长时间存储或提交。为了证明VOAuth可以有效地避免网络钓鱼攻击,特别是伪造Authorization Server,在Alloy Analyzer中显示了针对网络钓鱼威胁模型的对策和VOAuth中的形式验证。最后,VOAuth是在实际的移动Internet应用程序中实现的,并且已经有超过1500万用户使用了两年多的时间。到目前为止,还没有发生用户隐私数据的泄漏,也没有报告任何欺诈帐户,这为VOAuth的有效性提供了进一步的证据。 (C)2016由Elsevier B.V.发布

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号