首页> 外文OA文献 >Stronger Authentication for Password Credential Internet Services
【2h】

Stronger Authentication for Password Credential Internet Services

机译:密码凭据Internet服务的更强身份验证

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Most Web and other on-line service providers (”Inter- net Services”) only support legacy ID (or email) and password (ID/PW) credential authentication. However, there are numerous vulnerabilities concerning ID/PW credentials. Scholars and the industry have proposed several improved security solutions, such as MFA, however most of the Internet Services have refused to adopt these solutions. Mobile phones are much more sensitive to these vulnerabilities (so this paper focuses on mobile phones). Many users take advantage of password managers, to keep track of all their Internet Service profiles. However, the Internet Service profiles found in password managers, are normally kept on the PC or mobile phone’s disk, in an encrypted form. Our first contribution is a design guideline, whereby the Internet Service profiles never need to touch the client’s disk. Most users would benefit, if they had the ability to use MFA, to login to a legacy Internet Service, which only supports ID/PW credential authentication. Our second contribution is a design guideline, whereby users can choose, for each legacy ID/PW Internet Service, which specific MFA they wish to use. We have also presenting conceptual design guidelines, showing that both of our contributions are minor changes to existing password managers, which can be implemented easily with low overhead.
机译:大多数Web和其他在线服务提供商(“ Internet服务”)仅支持旧版ID(或电子邮件)和密码(ID / PW)凭据身份验证。但是,存在许多与ID / PW凭据有关的漏洞。学者和业界已经提出了几种改进的安全解决方案,例如MFA,但是大多数Internet服务都拒绝采用这些解决方案。手机对这些漏洞更加敏感(因此,本文重点关注手机)。许多用户利用密码管理器来跟踪其所有Internet服务配置文件。但是,在密码管理器中找到的Internet服务配置文件通常以加密形式保存在PC或手机的磁盘上。我们的第一个贡献是设计指南,通过该指南,Internet服务配置文件无需接触客户的磁盘。如果大多数用户能够使用MFA,他们将受益于登录仅支持ID / PW凭据身份验证的旧版Internet服务。我们的第二个贡献是设计指南,用户可以为每个旧版ID / PW Internet服务选择他们希望使用的特定MFA。我们还提出了概念设计指南,表明我们的两个贡献都是对现有密码管理器的微小更改,可以轻松以较低的开销实现。

著录项

  • 作者

    Booth, Todd; Andersson, Karl;

  • 作者单位
  • 年度 2017
  • 总页数
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号