Breaking Randomized Linear Generation Functions Based Virtual Password System
Breaking Randomized Linear Generation Functions Based Virtual Password System
复制标题
基于随机线性生成函数的虚拟密码系统的破解
DOI:
10.1109/icc.2010.5502416
复制
发表时间:
2010
期刊:
影响因子:
--
通讯作者:
R. Schmitz
中科院分区:
文献类型:
--
作者:
Shujun Li;S. A. Khayam;A. Sadeghi;R. Schmitz
In ICC2008 and subsequent work, Lei et al. proposed a user authentication system (virtual password system), which is claimed to be secure against identity theft attacks, including phishing, keylogging and shoulder surfing. Their authentication system is a challenge-response protocol based on a randomized linear generation function, which uses a random integer in the responses of each login session to offer security against assorted attacks. In this paper we show that their virtual password system is insecure and vulnerable to multiple attacks. We show that with high probability an attacker can recover an equivalent password with only two (or a few more) observed login sessions. We also give a brief survey of the related work and discuss the main challenges in designing user authentication methods secure against identity theft.