Enhancing Performance of User Authentication Protocol with Resist to Password Reuse Attacks

Enhancing Performance of User Authentication Protocol with Resist to Password Reuse Attacks
复制标题

增强用户认证协议的性能并抵抗密码重用攻击

DOI:
--
复制
发表时间:
2012
期刊:
影响因子:
--
通讯作者:
Aravindhan Kurunthachalam
Aravindhan Kurunthachalam
中科院分区:
--
文献类型:
--
作者:
Aravindhan Kurunthachalam

文献摘要

被引文献

相似文献

文本密码因其方便性和简单性而成为网站上最受欢迎的用户身份验证形式。然而,用户的密码很容易被窃取,并受到不同的威胁和漏洞。用户经常选择弱密码,并在不同的网站上重复使用相同的密码。输入密码到不受信任的计算机遭受密码窃贼的威胁。用户身份验证协议提出了oPass增强功能来保护用户身份;它需要一个长期密码来保护手机,并需要帐户ID来登录所有网站。OPass只要求每个参与网站拥有唯一的电话号码,并在注册和恢复阶段涉及电信服务提供商,以创建一次性密码。用户可以恢复oPass系统与补发SIM卡和长期密码。与传统的Web身份验证机制相比,Opass是高效且经济的。因此,一次性密码机制使用私钥基础设施增强了安全性,以防止由于网络钓鱼攻击和键盘记录程序而导致的完整性问题。网络安全,密码重复使用攻击,密码窃取攻击,用户认证。
Text password is the most popular form of user authentication on websites due to its convenience and simplicity. However, user’s passwords are prone to be stolen and compromised by different threats and vulnerabilities. Users often select weak passwords and reuse the same passwords across different websites. Typing passwords into untrusted computers suffers password thief threat. The user authentication protocol proposes the oPass enhancement to protect user identity; it requires a long-term password for cell phone protection and account ID for login on all websites. OPass only requires each participating website possesses a unique phone number, and involves a telecommunication service provider in registration and recovery phases for the creation of one-time password. User can recover oPass system with reissued SIM cards and long-term passwords. Opass is efficient and affordable compared with the conventional web authentication mechanisms. Therefore one-time password mechanism that has enhanced security using private key infrastructure to prevent integrity problem due to phishing attack and keyloggers. Index Terms—Network security, password reuse attack, pass- word stealing attack, user authentication.