Two Birds with One Stone: Two-Factor Authentication with Security Beyond Conventional Bound

Two Birds with One Stone: Two-Factor Authentication with Security Beyond Conventional Bound
复制标题

一石二鸟:双因素身份验证,安全性超越传统界限

DOI:
10.1109/tdsc.2016.2605087
复制
发表时间:
2018-07-01
影响因子:
7.3
通讯作者:
Wang, Ping
Wang, Ping
中科院分区:
计算机科学2区
文献类型:
--
作者:
Wang, Ding;Wang, Ping

文献摘要

被引文献

相似文献

基于智能卡的口令认证作为目前最流行的双因素认证机制,在过去的二十年里得到了广泛的研究,涌现出了数以百计的这类认证方案。在大多数这些研究中,有没有全面和系统的度量方案进行客观评估,作者提出了新的方案与断言的上级方面比以前的,而忽略的尺寸上,他们的计划票价不佳。毫不奇怪,它们中的大多数都是不可靠的要么是缺少重要的安全目标,要么是缺少关键属性,尤其是在安全性和可用性之间的紧张关系中。为了克服这个问题,在这项工作中,我们首先明确定义了一个安全模型,可以准确地捕捉对手的实际能力,然后建议一个广泛的一组12属性框架作为一个系统的方法进行比较评估,允许计划在一个共同的频谱进行评级。作为我们的主要贡献,提出了一个新的计划,以解决所产生的各种问题,用户腐败和服务器妥协,并正式证明了安全的最苛刻的对手模型。特别是,通过集成“蜜词”,传统上的系统安全的范围内,与“模糊验证器”,我们的计划击中“两只鸟”:它不仅消除了长期存在的安全性可用性的冲突,被认为是棘手的文献中,但也实现了安全保证超出了传统的最佳安全界限。
As the most prevailing two-factor authentication mechanism, smart-card-based password authentication has been a subject of intensive research in the past two decades, and hundreds of this type of schemes have wave upon wave been proposed. In most of these studies, there is no comprehensive and systematical metric available for schemes to be assessed objectively, and the authors present new schemes with assertions of the superior aspects over previous ones, while overlooking dimensions on which their schemes fare poorly. Unsurprisingly, most of them are far from satisfactory—either are found short of important security goals or lack of critical properties, especially being stuck with the security-usability tension. To overcome this issue, in this work we first explicitly define a security model that can accurately capture the practical capabilities of an adversary and then suggest a broad set of twelve properties framed as a systematic methodology for comparative evaluation, allowing schemes to be rated across a common spectrum. As our main contribution, a new scheme is advanced to resolve the various issues arising from user corruption and server compromise, and it is formally proved secure under the harshest adversary model so far. In particular, by integrating “honeywords”, traditionally the purview of system security, with a “fuzzy-verifier”, our scheme hits “two birds”: it not only eliminates the long-standing security-usability conflict that is considered intractable in the literature, but also achieves security guarantees beyond the conventional optimal security bound.