Breaking Randomized Linear Generation Functions Based Virtual Password System

Breaking Randomized Linear Generation Functions Based Virtual Password System
复制标题

基于随机线性生成函数的虚拟密码系统的破解

DOI:
10.1109/icc.2010.5502416
复制
发表时间:
2010
期刊:
IEEE International Conference on Communications
影响因子:
--
通讯作者:
R. Schmitz
R. Schmitz
中科院分区:
--
文献类型:
--
作者:
Shujun Li;S. A. Khayam;A. Sadeghi;R. Schmitz

文献摘要

被引文献

相似文献

在ICC 2008及随后的工作中,Lei等人提出了一种用户身份验证系统(虚拟密码系统),该系统声称可以防止身份盗窃攻击,包括网络钓鱼,键盘记录和肩击。他们的认证系统是基于随机线性生成函数的挑战-响应协议,该协议在每个登录会话的响应中使用随机整数来提供针对各种攻击的安全性。在本文中,我们证明了他们的虚拟密码系统是不安全的,并且容易受到多种攻击。我们表明,攻击者可以恢复一个等效的密码只有两个(或几个)观察到的登录会话的概率很高。我们还简要介绍了相关的工作,并讨论了在设计用户身份验证方法的主要挑战,防止身份盗窃。
In ICC2008 and subsequent work, Lei et al. proposed a user authentication system (virtual password system), which is claimed to be secure against identity theft attacks, including phishing, keylogging and shoulder surfing. Their authentication system is a challenge-response protocol based on a randomized linear generation function, which uses a random integer in the responses of each login session to offer security against assorted attacks. In this paper we show that their virtual password system is insecure and vulnerable to multiple attacks. We show that with high probability an attacker can recover an equivalent password with only two (or a few more) observed login sessions. We also give a brief survey of the related work and discuss the main challenges in designing user authentication methods secure against identity theft.