BetterAuth: web authentication revisited

BetterAuth: web authentication revisited
复制标题

BetterAuth:重新审视网络身份验证

DOI:
--
复制
发表时间:
2012
期刊:
Asia-Pacific Computer Systems Architecture Conference
影响因子:
--
通讯作者:
Benjamin Flesch
Benjamin Flesch
中科院分区:
--
文献类型:
--
作者:
Martin Johns;Sebastian Lekies;Bastian Braun;Benjamin Flesch

文献摘要

被引文献

相似文献

提出了一种Web应用程序的认证协议BetterAuth。它的设计是基于20年的网络经验。BetterAuth解决了现有的对Web身份验证的攻击,从网络攻击到跨站点请求伪造到网络钓鱼。此外,该协议可以完全在标准JavaScript中实现。这使得Web应用程序能够尽早采用,即使在浏览器支持有限的情况下也是如此。
This paper presents "BetterAuth", an authentication protocol for Web applications. Its design is based on the experiences of two decades with the Web. BetterAuth addresses existing attacks on Web authentication, ranging from network attacks to Cross-site Request Forgery up to Phishing. Furthermore, the protocol can be realized completely in standard JavaScript. This allows Web applications an early adoption, even in a situation with limited browser support.