Enhancing Performance of User Authentication Protocol with Resist to Password Reuse Attacks
Enhancing Performance of User Authentication Protocol with Resist to Password Reuse Attacks
复制标题
增强用户认证协议的性能并抵抗密码重用攻击
DOI:
--
复制
发表时间:
2012
期刊:
影响因子:
--
通讯作者:
Aravindhan Kurunthachalam
中科院分区:
文献类型:
--
作者:
Aravindhan Kurunthachalam
Text password is the most popular form of user authentication on websites due to its convenience and simplicity. However, user’s passwords are prone to be stolen and compromised by different threats and vulnerabilities. Users often select weak passwords and reuse the same passwords across different websites. Typing passwords into untrusted computers suffers password thief threat. The user authentication protocol proposes the oPass enhancement to protect user identity; it requires a long-term password for cell phone protection and account ID for login on all websites. OPass only requires each participating website possesses a unique phone number, and involves a telecommunication service provider in registration and recovery phases for the creation of one-time password. User can recover oPass system with reissued SIM cards and long-term passwords. Opass is efficient and affordable compared with the conventional web authentication mechanisms. Therefore one-time password mechanism that has enhanced security using private key infrastructure to prevent integrity problem due to phishing attack and keyloggers. Index Terms—Network security, password reuse attack, pass- word stealing attack, user authentication.