CICI: Secure Data Architecture: Improving the Security and Usability of Two-Factor Authentication for Cyberinfrastructure
CICI:安全数据架构:提高网络基础设施双因素身份验证的安全性和可用性
基本信息
- 批准号:1547435
- 负责人:
- 金额:$ 24.96万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Standard Grant
- 财政年份:2016
- 资助国家:美国
- 起止时间:2016-01-01 至 2018-12-31
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
Password authentication is a critical vulnerability in cyberinfrastructure because typical passwords are memorable and easily guessed, leaving them vulnerable to malicious actors. One well-recognized method for strengthening the password security is Two-Factor Authentication (TFA), in which the password is complemented by an additional authentication factor such as a mobile phone or a dedicated token (e.g., a USB dongle). However, current TFA mechanisms do not offer sufficient security and usability. This project breaks new ground towards improving both of these aspects. It designs, implements and evaluates TFA schemes that not only protect against on-line guessing attacks, but also against off-line dictionary attacks in case of server or mobile device compromise. Moreover, the project aims to do so without degrading usability compared to password-only authentication. The creation of formal security models for TFA schemes allow for better understanding of TFA security in general. The resulting research prototypes will be of immense value in future research on building resilient and usable authentication services. The project integrates research into educational activities in the form of advanced curriculum development as well as high school and K-12 student mentoring in the area of Identity and Access Management.The design of new TFA protocols offers security against on-line guessing and offline dictionary attacks. The project formally proves the security of these protocols in a strong security model for TFA protocols that is being introduced as an extension to well-established password-authenticated key exchange (PAKE) models. The goal is to design the TFA protocols in a modular way, allowing for the use of independent device and server components, and enabling the use of the developed schemes with existing password protocols and without the need to modify the server software. Moreover, the research involves developing and testing TFA systems which will instantiate the proposed protocols. The goal is a TFA systems design that utilizes automated and user-transparent data channel between the mobile device and the client, falling back to localized wireless radio communication only when such a channel is unavailable. Such construction would provide high usability since the user experience of the login process would be almost equivalent to password-only authentication. Finally, the project involves conducting rigorous usability studies in the lab environment and field settings to evaluate the performance, usability, and adoption potential of the proposed approaches.
密码认证是网络基础设施中的一个关键漏洞,因为典型的密码容易被记住,而且很容易被猜到,这使它们容易受到恶意行为者的攻击。一种公认的加强密码安全性的方法是双因素身份验证(TFA),其中密码由额外的身份验证因素补充,例如移动电话或专用令牌(例如USB加密狗)。然而,目前的TFA机制不能提供足够的安全性和可用性。这个项目为改善这两个方面开辟了新天地。它设计,实现和评估TFA方案,不仅可以防止在线猜测攻击,还可以防止离线字典攻击,以防服务器或移动设备受损。此外,与纯密码身份验证相比,该项目的目标是在不降低可用性的情况下这样做。为TFA方案创建正式的安全模型可以更好地理解TFA安全性。由此产生的研究原型将对未来构建弹性和可用的认证服务的研究具有巨大的价值。该项目以高级课程开发的形式将研究整合到教育活动中,并在身份和访问管理领域为高中和K-12学生提供指导。新的TFA协议的设计提供了针对在线猜测和离线字典攻击的安全性。该项目在TFA协议的强大安全模型中正式证明了这些协议的安全性,该模型是作为已建立的密码认证密钥交换(PAKE)模型的扩展引入的。目标是以模块化的方式设计TFA协议,允许使用独立的设备和服务器组件,并使开发的方案能够与现有的密码协议一起使用,而无需修改服务器软件。此外,研究还涉及开发和测试TFA系统,以实例化所提出的协议。目标是TFA系统设计利用移动设备和客户端之间的自动化和用户透明的数据通道,仅在该通道不可用时才退回到本地化的无线无线电通信。这种结构将提供高可用性,因为登录过程的用户体验几乎等同于纯密码身份验证。最后,该项目涉及在实验室环境和现场设置中进行严格的可用性研究,以评估所建议方法的性能、可用性和采用潜力。
项目成果
期刊论文数量(1)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
Password-Authenticated Public-Key Encryption
- DOI:10.1007/978-3-030-21568-2_22
- 发表时间:2019-06
- 期刊:
- 影响因子:0
- 作者:Tatiana Bradley;J. Camenisch;Stanislaw Jarecki;Anja Lehmann;G. Neven;Jiayu Xu
- 通讯作者:Tatiana Bradley;J. Camenisch;Stanislaw Jarecki;Anja Lehmann;G. Neven;Jiayu Xu
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Stanislaw Jarecki其他文献
Negotiated privacy
协商隐私
- DOI:
- 发表时间:
2002 - 期刊:
- 影响因子:0
- 作者:
Stanislaw Jarecki;P. Lincoln;Vitaly Shmatikov - 通讯作者:
Vitaly Shmatikov
Probabilistic Escrow of Financial Transactions with Cumulative Threshold Disclosure
具有累积阈值披露的金融交易的概率托管
- DOI:
10.1007/11507840_17 - 发表时间:
2005 - 期刊:
- 影响因子:0
- 作者:
Stanislaw Jarecki;Vitaly Shmatikov - 通讯作者:
Vitaly Shmatikov
Optimal Signcryption from Any Trapdoor Permutation
任何陷门排列的最佳签密
- DOI:
- 发表时间:
2004 - 期刊:
- 影响因子:0
- 作者:
Y. Dodis;M. Freedman;Stanislaw Jarecki;Shabsi Walfish - 通讯作者:
Shabsi Walfish
Three-Party ORAM for Secure Computation
用于安全计算的三方 ORAM
- DOI:
10.1007/978-3-662-48797-6_16 - 发表时间:
2015 - 期刊:
- 影响因子:0
- 作者:
Sky Faber;Stanislaw Jarecki;S. Kentros;Boyang Wei - 通讯作者:
Boyang Wei
Brief announcement: secret handshakes from CA-oblivious encryption
简短公告:来自 CA 不经意加密的秘密握手
- DOI:
- 发表时间:
2004 - 期刊:
- 影响因子:0
- 作者:
C. Castelluccia;Stanislaw Jarecki;G. Tsudik - 通讯作者:
G. Tsudik
Stanislaw Jarecki的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Stanislaw Jarecki', 18)}}的其他基金
Collaborative Research: SaTC: TTP: Medium: Intrusion-Tolerant Outsourced Storage for Cyber-Infrastructure
协作研究:SaTC:TTP:中:网络基础设施的耐入侵外包存储
- 批准号:
2030575 - 财政年份:2020
- 资助金额:
$ 24.96万 - 项目类别:
Standard Grant
SaTC: CORE: Small: Secure Computation on Large Data
SaTC:核心:小型:大数据安全计算
- 批准号:
1817143 - 财政年份:2018
- 资助金额:
$ 24.96万 - 项目类别:
Standard Grant
CAREER: Secure Multi-Party Protocols
职业:安全多方协议
- 批准号:
0747541 - 财政年份:2008
- 资助金额:
$ 24.96万 - 项目类别:
Continuing Grant
Privacy-Protecting Mechanisms for Data Escrow and Transaction Monitoring
数据托管和交易监控的隐私保护机制
- 批准号:
0430622 - 财政年份:2004
- 资助金额:
$ 24.96万 - 项目类别:
Continuing Grant
相似海外基金
CICI: UCSS: Maximizing Data Utility and Participant Privacy through Usable, Secure Data Workflows for Human-Centered AI Research
CICI:UCSS:通过可用、安全的数据工作流程实现以人为本的人工智能研究,最大限度地提高数据效用和参与者隐私
- 批准号:
2232690 - 财政年份:2023
- 资助金额:
$ 24.96万 - 项目类别:
Standard Grant
CICI: UCSS: Enhancing Integrity and Confidentiality for Secure Distributed Data Sharing
CICI:UCSS:增强安全分布式数据共享的完整性和保密性
- 批准号:
2114202 - 财政年份:2021
- 资助金额:
$ 24.96万 - 项目类别:
Standard Grant
CICI: RDP: Open Badge Researcher Credentials for Secure Access to Restricted and Sensitive Data
CICI:RDP:用于安全访问受限和敏感数据的开放徽章研究人员证书
- 批准号:
1839868 - 财政年份:2018
- 资助金额:
$ 24.96万 - 项目类别:
Standard Grant
CICI: SSC: Development of a Secure and Privacy-Preserving Workflow Architecture for Dynamic Data Sharing in Scientific Infrastructures
CICI:SSC:开发安全且保护隐私的工作流程架构,用于科学基础设施中的动态数据共享
- 批准号:
1839746 - 财政年份:2018
- 资助金额:
$ 24.96万 - 项目类别:
Standard Grant
CICI: Secure and Resilient Architecture: Campus Infrastructure for Microscale, Privacy-Conscious, Data-Driven Planning
CICI:安全和弹性架构:用于微型、隐私意识、数据驱动规划的园区基础设施
- 批准号:
1642120 - 财政年份:2017
- 资助金额:
$ 24.96万 - 项目类别:
Standard Grant
CICI: CE: SciTokens: Capability-Based Secure Access to Remote Scientific Data
CICI:CE:SciTokens:基于能力的远程科学数据安全访问
- 批准号:
1738962 - 财政年份:2017
- 资助金额:
$ 24.96万 - 项目类别:
Standard Grant
CICI: Secure Data Architecture: Ensuring Data Integrity at the Beginning of the Scientific Workflow; A Mini-ScienceDMZ for Instruments
CICI:安全数据架构:在科学工作流程开始时确保数据完整性;
- 批准号:
1547099 - 财政年份:2016
- 资助金额:
$ 24.96万 - 项目类别:
Standard Grant
CICI: Secure Data Architecture: Collaborative Research: Assured Mission Delivery Network Framework for Secure Scientific Collaboration
CICI:安全数据架构:协作研究:确保安全科学协作的任务交付网络框架
- 批准号:
1547390 - 财政年份:2016
- 资助金额:
$ 24.96万 - 项目类别:
Standard Grant
CICI: Secure Data Architecture: Collaborative Research: Assured Mission Delivery Network Framework for Secure Scientific Collaboration
CICI:安全数据架构:协作研究:确保安全科学协作的任务交付网络框架
- 批准号:
1547411 - 财政年份:2016
- 资助金额:
$ 24.96万 - 项目类别:
Standard Grant
CICI: Secure Data Architecture: CILogon 2.0 - An Integrated Identity and Access Management Platform for Science
CICI:安全数据架构:CILogon 2.0 - 科学的集成身份和访问管理平台
- 批准号:
1547268 - 财政年份:2016
- 资助金额:
$ 24.96万 - 项目类别:
Standard Grant