首页> 外文OA文献 >Protecting Web Passwords from Rogue Servers using Trusted Execution Environments
【2h】

Protecting Web Passwords from Rogue Servers using Trusted Execution Environments

机译:使用可信执行保护来自恶意服务器的Web密码   环境

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Passwords are undoubtedly the most dominant user authentication mechanism onthe web today. Although they are inexpensive and easy-to-use, security concernsof password-based authentication are serious. Phishing and theft of passworddatabases are two critical concerns. The tendency of users to re-use passwordsacross different services exacerbates the impact of these two concerns. Currentsolutions addressing these concerns are not fully satisfactory: they typicallyaddress only one of the two concerns; they do not protect passwords from rogueservers; they do not provide any verifiable evidence of their (server-side)adoption to users; and they face deployability challenges in terms of the costfor service providers and/or ease-of-use for end users. We present SafeKeeper, a comprehensive approach to protect theconfidentiality of passwords in web authentication systems. Unlike previousapproaches, SafeKeeper protects user passwords against very strong adversaries,including rogue servers and sophisticated external phishers. It is relativelyinexpensive to deploy as it (i) uses widely available hardware securitymechanisms like Intel SGX, (ii) is integrated into popular web platforms likeWordPress, and (iii) has small performance overhead. We describe a variety ofchallenges in designing and implementing such a system, and how we overcomethem. Through an 86-participant user study, and systematic analysis andexperiments, we demonstrate the usability, security and deployability ofSafeKeeper, which is available as open-source.
机译:毫无疑问,密码是当今网络上最主要的用户身份验证机制。尽管它们便宜且易于使用,但是基于密码的身份验证的安全性问题还是很严重的。密码数据库的网络钓鱼和盗窃是两个关键问题。用户跨不同服务重用密码的趋势加剧了这两个问题的影响。解决这些问题的当前解决方案并不完全令人满意:它们通常仅解决两个问题之一;它们不保护来自恶意服务器的密码;他们没有向用户提供任何有关其(服务器端)采用的可验证证据;并且在服务提供商的成本和/或最终用户的易用性方面,他们面临可部署性方面的挑战。我们提出了SafeKeeper,这是一种用于保护Web身份验证系统中密码机密性的综合方法。与以前的方法不同,SafeKeeper可以保护用户密码免受非常强大的对手的攻击,包括恶意服务器和复杂的外部网络钓鱼者。部署它相对便宜,因为(i)使用广泛使用的硬件安全机制,例如Intel SGX,(ii)集成到流行的Web平台(如WordPress)中,并且(iii)性能开销很小。我们描述了设计和实施这种系统的各种挑战,以及我们如何克服这些挑战。通过86位用户的研究,以及系统的分析和实验,我们演示了SafeKeeper的可用性,安全性和可部署性,可以将其作为开放源代码使用。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号