CICI: Secure Data Architecture: Improving the Security and Usability of Two-Factor Authentication for Cyberinfrastructure

CICI:安全数据架构:提高网络基础设施双因素身份验证的安全性和可用性

基本信息

  • 批准号:
    1547350
  • 负责人:
  • 金额:
    $ 24.97万
  • 依托单位:
  • 依托单位国家:
    美国
  • 项目类别:
    Standard Grant
  • 财政年份:
    2016
  • 资助国家:
    美国
  • 起止时间:
    2016-01-01 至 2021-06-30
  • 项目状态:
    已结题

项目摘要

Password authentication is a critical vulnerability in cyberinfrastructure because typical passwords are memorable and easily guessed, leaving them vulnerable to malicious actors. One well-recognized method for strengthening the password security is Two-Factor Authentication (TFA), in which the password is complemented by an additional authentication factor such as a mobile phone or a dedicated token (e.g., a USB dongle). However, current TFA mechanisms do not offer sufficient security and usability. This project breaks new ground towards improving both of these aspects. It designs, implements and evaluates TFA schemes that not only protect against on-line guessing attacks, but also against off-line dictionary attacks in case of server or mobile device compromise. Moreover, the project aims to do so without degrading usability compared to password-only authentication. The creation of formal security models for TFA schemes allow for better understanding of TFA security in general. The resulting research prototypes will be of immense value in future research on building resilient and usable authentication services. The project integrates research into educational activities in the form of advanced curriculum development as well as high school and K-12 student mentoring in the area of Identity and Access Management.The design of new TFA protocols offers security against on-line guessing and offline dictionary attacks. The project formally proves the security of these protocols in a strong security model for TFA protocols that is being introduced as an extension to well-established password-authenticated key exchange (PAKE) models. The goal is to design the TFA protocols in a modular way, allowing for the use of independent device and server components, and enabling the use of the developed schemes with existing password protocols and without the need to modify the server software. Moreover, the research involves developing and testing TFA systems which will instantiate the proposed protocols. The goal is a TFA systems design that utilizes automated and user-transparent data channel between the mobile device and the client, falling back to localized wireless radio communication only when such a channel is unavailable. Such construction would provide high usability since the user experience of the login process would be almost equivalent to password-only authentication. Finally, the project involves conducting rigorous usability studies in the lab environment and field settings to evaluate the performance, usability, and adoption potential of the proposed approaches.
密码认证是网络基础设施中的一个关键漏洞,因为典型的密码容易记忆且容易被猜测,使其容易受到恶意行为者的攻击。一种公认的加强密码安全性的方法是双因素身份验证(TFA),其中密码由额外的身份验证因素(例如移动的电话或专用令牌(例如,USB加密狗)。然而,目前的TFA机制不提供足够的安全性和可用性。该项目为改善这两个方面开辟了新的天地。设计、实现并评估了TFA方案,该方案不仅能抵抗在线猜测攻击,还能抵抗服务器或移动终端受到攻击时的离线字典攻击。此外,该项目的目标是这样做,而不降低可用性相比,密码只有身份验证。为TFA方案创建正式的安全模型,可以更好地理解TFA的安全性。由此产生的研究原型将是巨大的价值,在未来的研究建设弹性和可用的认证服务。该项目以高级课程开发以及高中和K-12学生在身份和访问管理领域的指导的形式将研究融入教育活动。新的TFA协议的设计提供了对在线猜测和离线字典攻击的安全性。该项目正式证明了这些协议的安全性,在一个强大的安全模型TFA协议,被引入作为一个扩展,完善的密码认证密钥交换(PAKE)模型。目标是以模块化的方式设计TFA协议,允许使用独立的设备和服务器组件,并使开发的方案能够与现有的密码协议一起使用,而无需修改服务器软件。此外,研究涉及开发和测试TFA系统,将实例化所提出的协议。 目标是一种TFA系统设计,其利用移动终端和客户端之间的自动化和用户透明的数据信道,仅当这样的信道不可用时才退回到局部无线电通信。这种构造将提供高可用性,因为登录过程的用户体验将几乎等同于仅密码认证。最后,该项目涉及在实验室环境和现场环境中进行严格的可用性研究,以评估所提出的方法的性能,可用性和采用潜力。

项目成果

期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ monograph.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ sciAawards.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ conferencePapers.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ patent.updateTime }}

Nitesh Saxena其他文献

PASSAT: Single Password Authenticated Secret-Shared Intrusion-Tolerant Storage with Server Transparency
PASSAT:具有服务器透明性的单密码验证秘密共享入侵容忍存储
  • DOI:
  • 发表时间:
    2021
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Kiavash Satvat;Maliheh Shirvanian;Nitesh Saxena
  • 通讯作者:
    Nitesh Saxena
Public Key Cryptography Sans Certificates in Ad Hoc Networks
Ad Hoc 网络中的公钥加密无证书
Gene Regulation and Species-Specific Evolution of Free Flight Odor Tracking in Drosophila
果蝇自由飞行气味追踪的基因调控和物种特异性进化
  • DOI:
    10.1093/molbev/msx241
  • 发表时间:
    2018
  • 期刊:
  • 影响因子:
    10.7
  • 作者:
    B. Houot;Laurie Cazalé;S. Fraichard;C. Everaerts;Nitesh Saxena;S. Sane;J. Ferveur
  • 通讯作者:
    J. Ferveur
Robust self-keying mobile ad hoc networks
强大的自键控移动自组织网络
  • DOI:
    10.1016/j.comnet.2006.07.009
  • 发表时间:
    2007
  • 期刊:
  • 影响因子:
    0
  • 作者:
    C. Castelluccia;Nitesh Saxena;J. Yi
  • 通讯作者:
    J. Yi
Towards Sensing-Enabled RFID Security and Privacy
迈向传感型 RFID 安全和隐私

Nitesh Saxena的其他文献

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

{{ truncateString('Nitesh Saxena', 18)}}的其他基金

Collaborative Research: SaTC: CORE: Medium: Bubble Aid: Assistive AI to Improve the Robustness and Security of Reading Hand-Marked Ballots
合作研究:SaTC:核心:媒介:Bubble Aid:辅助人工智能提高阅读手写选票的稳健性和安全性
  • 批准号:
    2154507
  • 财政年份:
    2022
  • 资助金额:
    $ 24.97万
  • 项目类别:
    Continuing Grant
CICI: UCSS: Towards Secure and Usable Push Notification Authentication for Collaborative Scientific Infrastructures
CICI:UCSS:为协作科学基础设施实现安全可用的推送通知身份验证
  • 批准号:
    2115107
  • 财政年份:
    2021
  • 资助金额:
    $ 24.97万
  • 项目类别:
    Standard Grant
CICI: UCSS: Towards Secure and Usable Push Notification Authentication for Collaborative Scientific Infrastructures
CICI:UCSS:为协作科学基础设施实现安全可用的推送通知身份验证
  • 批准号:
    2139358
  • 财政年份:
    2021
  • 资助金额:
    $ 24.97万
  • 项目类别:
    Standard Grant
Collaborative Research: SaTC: TTP: Medium: Intrusion-Tolerant Outsourced Storage for Cyber-Infrastructure
协作研究:SaTC:TTP:中:网络基础设施的耐入侵外包存储
  • 批准号:
    2201465
  • 财政年份:
    2021
  • 资助金额:
    $ 24.97万
  • 项目类别:
    Standard Grant
SaTC: TTP: Small: SPHINX: A Password Store that Perfectly Hides Passwords from Itself
SaTC:TTP:小型:SPHINX:完美隐藏密码的密码存储
  • 批准号:
    2152669
  • 财政年份:
    2021
  • 资助金额:
    $ 24.97万
  • 项目类别:
    Standard Grant
Collaborative Research: SaTC: TTP: Medium: Intrusion-Tolerant Outsourced Storage for Cyber-Infrastructure
协作研究:SaTC:TTP:中:网络基础设施的耐入侵外包存储
  • 批准号:
    2030501
  • 财政年份:
    2020
  • 资助金额:
    $ 24.97万
  • 项目类别:
    Standard Grant
SaTC: TTP: Small: SPHINX: A Password Store that Perfectly Hides Passwords from Itself
SaTC:TTP:小型:SPHINX:完美隐藏密码的密码存储
  • 批准号:
    1714807
  • 财政年份:
    2017
  • 资助金额:
    $ 24.97万
  • 项目类别:
    Standard Grant
TWC: Small: Collaborative: Spoof-Resistant Smartphone Authentication using Cooperating Wearables
TWC:小型:协作:使用协作可穿戴设备进行防欺骗智能手机身份验证
  • 批准号:
    1526524
  • 财政年份:
    2015
  • 资助金额:
    $ 24.97万
  • 项目类别:
    Standard Grant
CT-ISG: User-Aided Secure Association of Wireless Devices
CT-ISG:用户辅助的无线设备安全关联
  • 批准号:
    1228236
  • 财政年份:
    2012
  • 资助金额:
    $ 24.97万
  • 项目类别:
    Standard Grant
EAGER: Establishing Secure Wireless Connections via Playful User Engagement
EAGER:通过有趣的用户参与建立安全的无线连接
  • 批准号:
    1255919
  • 财政年份:
    2012
  • 资助金额:
    $ 24.97万
  • 项目类别:
    Standard Grant

相似海外基金

CICI: UCSS: Maximizing Data Utility and Participant Privacy through Usable, Secure Data Workflows for Human-Centered AI Research
CICI:UCSS:通过可用、安全的数据工作流程实现以人为本的人工智能研究,最大限度地提高数据效用和参与者隐私
  • 批准号:
    2232690
  • 财政年份:
    2023
  • 资助金额:
    $ 24.97万
  • 项目类别:
    Standard Grant
CICI: UCSS: Enhancing Integrity and Confidentiality for Secure Distributed Data Sharing
CICI:UCSS:增强安全分布式数据共享的完整性和保密性
  • 批准号:
    2114202
  • 财政年份:
    2021
  • 资助金额:
    $ 24.97万
  • 项目类别:
    Standard Grant
CICI: RDP: Open Badge Researcher Credentials for Secure Access to Restricted and Sensitive Data
CICI:RDP:用于安全访问受限和敏感数据的开放徽章研究人员证书
  • 批准号:
    1839868
  • 财政年份:
    2018
  • 资助金额:
    $ 24.97万
  • 项目类别:
    Standard Grant
CICI: SSC: Development of a Secure and Privacy-Preserving Workflow Architecture for Dynamic Data Sharing in Scientific Infrastructures
CICI:SSC:开发安全且保护隐私的工作流程架构,用于科学基础设施中的动态数据共享
  • 批准号:
    1839746
  • 财政年份:
    2018
  • 资助金额:
    $ 24.97万
  • 项目类别:
    Standard Grant
CICI: Secure and Resilient Architecture: Campus Infrastructure for Microscale, Privacy-Conscious, Data-Driven Planning
CICI:安全和弹性架构:用于微型、隐私意识、数据驱动规划的园区基础设施
  • 批准号:
    1642120
  • 财政年份:
    2017
  • 资助金额:
    $ 24.97万
  • 项目类别:
    Standard Grant
CICI: CE: SciTokens: Capability-Based Secure Access to Remote Scientific Data
CICI:CE:SciTokens:基于能力的远程科学数据安全访问
  • 批准号:
    1738962
  • 财政年份:
    2017
  • 资助金额:
    $ 24.97万
  • 项目类别:
    Standard Grant
CICI: Secure Data Architecture: Ensuring Data Integrity at the Beginning of the Scientific Workflow; A Mini-ScienceDMZ for Instruments
CICI:安全数据架构:在科学工作流程开始时确保数据完整性;
  • 批准号:
    1547099
  • 财政年份:
    2016
  • 资助金额:
    $ 24.97万
  • 项目类别:
    Standard Grant
CICI: Secure Data Architecture: Collaborative Research: Assured Mission Delivery Network Framework for Secure Scientific Collaboration
CICI:安全数据架构:协作研究:确保安全科学协作的任务交付网络框架
  • 批准号:
    1547390
  • 财政年份:
    2016
  • 资助金额:
    $ 24.97万
  • 项目类别:
    Standard Grant
CICI: Secure Data Architecture: Collaborative Research: Assured Mission Delivery Network Framework for Secure Scientific Collaboration
CICI:安全数据架构:协作研究:确保安全科学协作的任务交付网络框架
  • 批准号:
    1547411
  • 财政年份:
    2016
  • 资助金额:
    $ 24.97万
  • 项目类别:
    Standard Grant
CICI: Secure Data Architecture: CILogon 2.0 - An Integrated Identity and Access Management Platform for Science
CICI:安全数据架构:CILogon 2.0 - 科学的集成身份和访问管理平台
  • 批准号:
    1547268
  • 财政年份:
    2016
  • 资助金额:
    $ 24.97万
  • 项目类别:
    Standard Grant
{{ showInfoDetail.title }}

作者:{{ showInfoDetail.author }}

知道了