首页> 外文OA文献 >Breaking Randomized Linear Generation Functions based Virtual Password System
【2h】

Breaking Randomized Linear Generation Functions based Virtual Password System

机译:打破随机线性生成函数的虚拟密码系统

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

In ICC2008 and subsequent work, Lei et al. proposed a user authentication system (virtual password system), which is claimed to be secure against identity theft attacks, including phishing, keylogging and shoulder surfing. Their authentication system is a challenge-response protocol based on a randomized linear generation function, which uses a random integer in the responses of each login session to offer security against assorted attacks. In this paper we show that their virtual password system is insecure and vulnerable to multiple attacks. We show that with high probability an attacker can recover an equivalent password with only two (or a few more) observed login sessions. We also give a brief survey of the related work and discuss the main challenges in designing user authentication methods secure against identity theft.
机译:在ICC2008及后续工作中,Lei等人。提出了一种用户身份验证系统(虚拟密码系统),该系统据称可防止身份盗窃攻击,包括网络钓鱼,键盘记录和肩膀冲浪。他们的身份验证系统是基于随机线性生成函数的质询响应协议,该协议在每个登录会话的响应中使用随机整数来提供针对各种攻击的安全性。在本文中,我们证明了他们的虚拟密码系统不安全并且容易受到多种攻击。我们证明,攻击者很可能仅观察到两个(或几个)登录会话即可恢复等效的密码。我们还对相关工作进行了简要调查,并讨论了设计可防止身份盗用的用户身份验证方法的主要挑战。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号