Two-factor authentication framework for private cloud

Two-factor authentication framework for private cloud
复制标题

私有云双因素认证框架

DOI:
10.1109/icstcc.2019.8885460
复制
发表时间:
2019
期刊:
2019 23rd International Conference on System Theory, Control and Computing (ICSTCC)
影响因子:
--
通讯作者:
A. Potorac
A. Potorac
中科院分区:
--
文献类型:
--
作者:
I. Gordin;A. Graur;A. Potorac

文献摘要

被引文献

相似文献

在过去的几年里,授权访问公共云已经从简单的用户身份验证和密码身份验证发展到双因素身份验证(TOTP),并增加了用于输入唯一代码的额外字段。今天,它被Facebook、微软、苹果等几乎所有主要网站使用,也是银行网站经常使用的解决方案。另一方面,像OpenStack、CloudStack或Eucalyptus这样的私有云解决方案并没有提供这种安全改进。本文介绍了这种新型身份验证的优点,并综合了主要云提供商使用的TOTP身份验证形式。此外,本文还提出了一个实用的解决方案,为OpenStack云添加双因素身份验证,以解决这一挑战。为此,修改了网络认证表格,并开发了一个新的认证模块。本文档还涵盖了添加TOTP用户、生成QR形式的密码并将其发送给用户的整个过程。该研究的结论是使用OpenStack工具来简化上述整个过程。
Authorizing access to the public cloud has evolved over the last few years, from simple user authentication and password authentication to two-factor authentication (TOTP), with the addition of an additional field for entering a unique code. Today it is used by almost all major websites such as Facebook, Microsoft, Apple and is a frequently used solution for banking websites. On the other side, the private cloud solutions like OpenStack, CloudStack or Eucalyptus doesn’t offer this security improvement. This article is presenting the advantages of this new type of authentication and synthetizes the TOTP authentication forms used by major cloud providers. Furthermore, the article is proposing to solve this challenge by presenting a practical solution for adding two-factor authentication for OpenStack cloud. For this purpose, the web authentication form has been modified and a new authentication module has been developed. The present document covers as well the entire process of adding a TOTP user, generating and sending the secret code in QR form to the user. The study concludes with OpenStack tools used for simplifying the entire process presented above.