Securing User Authentication in Emerging Threat Landscapes
Securing User Authentication in Emerging Threat Landscapes
批准号:
RGPIN-2021-03141
负责人:
Alaca, Furkan
金额:
$1.75万
依托单位:
依托单位国家:
加拿大
项目类别:
Discovery Grants Program - Individual
财政年份:
2022
资助国家:
加拿大
项目状态:
已结题
起止时间:
2022-01-01 至 2023-12-31
中文摘要
用户身份验证-在授予对系统的访问权之前验证用户声称的身份的过程-是防止未经授权使用计算系统的关键第一道防线。虽然密码仍然是用户身份验证的主要形式,但网络威胁的日益复杂和扩散导致加拿大和国际机构采用更强的身份验证方案,如双因素身份验证。然而,目前加强认证的方法只能在有限的情况下提供最大的好处,例如在拥有大型IT部门的组织中,这些部门可以提供必要的支持和培训,使所有用户都能普遍使用。多因素身份验证和密码管理是最重要的机制之一,可以防止安全漏洞造成的大多数损失。该研究计划的长期目标是改变用户身份验证的未来,允许用户使用方便,可用和可访问的方法进行身份验证,同时满足所有利益相关者(包括用户和在线服务提供商)明确定义的安全目标。这将通过使人们更容易在网上保护自己来改善人们的生活,并将减轻日益敌对的威胁环境给行业和政府带来的负担。为此,该研究计划将(1)通过大规模数据收集,检查安全文献中未经测试的假设在真实世界部署和使用身份验证系统中的适用性;(2)建立新的安全机制,解决比当前系统更广泛和更复杂的威胁,而不需要额外的用户努力;(3)设计新的认证方案,利用现代技术,如可信执行环境和物联网设备,以实现以前不可能实现的好处;(四)开发框架,安全从业人员可以使用这些框架从定制的已知组件组成身份验证系统,以实现特定上下文;以及(5)制定向用户传达威胁模型的方法,以帮助他们做出配置和使用身份验证系统的决策。2017年,五分之一的加拿大企业因网络安全攻击而遭受运营后果;此类攻击在加拿大每年造成的经济影响超过30亿美元。弱身份验证被认为是导致违规的主要原因。该研究计划将有助于开发安全机制和框架,以应对更强大的威胁,并系统地解决不同环境中的特定安全要求。它还将通过培训研究生和本科生成为高素质的安全专家来应对加拿大网络安全专业人员的短缺,加拿大最早将在2023年对多达53,000名专业人员的需求。
英文摘要
User authentication-the process of verifying the claimed identity of a user prior to granting access to a system-is a critical first line of defense against unauthorized use of computing systems. While passwords have remained the dominant form of user authentication, the increased sophistication and proliferation of cyberthreats is leading institutions in Canada and internationally to adopt stronger authentication schemes, such as two-factor authentication. However, current approaches to strengthen authentication provide maximum benefit only in limited contexts, such as in organizations with large IT departments that can provide the necessary support and training to enable universal use by all users. Multi-factor authentication and password management are known to be among the most important mechanisms that can prevent most losses caused by security breaches. The long-term objective of this research program is to transform the future of user authentication to allow users to authenticate using methods that are convenient, usable, and accessible, while meeting clearly-defined security goals of all stakeholders including users and online service providers. This will improve people's lives by making it easier for them to protect themselves online, and will reduce the burden imposed on industry and government by an increasingly hostile threat landscape. Toward that end, this research program will (1) Examine, via large-scale data collection, untested assumptions in security literature for their applicability in the real-world deployment and usage of authentication systems; (2) Build novel security mechanisms that address a wider and more sophisticated range of threats than current systems, without requiring additional user effort; (3) Design new authentication schemes that leverage modern technologies, such as trusted execution environments and Internet of Things devices, to achieve benefits that were not previously possible; (4) Develop frameworks that security practitioners can use to compose authentication systems from known components tailored to fulfill security objectives required for specific contexts; and (5) Formulate methods to communicate threat models to users to aid them in decision-making for configuring and using authentication systems. One fifth of Canadian businesses suffered operational consequences due to cybersecurity attacks in 2017; the economic impact of such attacks in Canada is over $3 billion annually. Weak authentication is recognized as a leading cause of breaches. This research program will be instrumental in developing security mechanisms and frameworks that counter a more powerful range of threats and systematically address specific security requirements in different contexts. It will also respond to the shortage of cybersecurity professionals in Canada, which will see a demand for up to 53,000 professionals as early as 2023, by training graduate and undergraduate students to be highly-qualified security experts.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Securing User Authentication in Emerging Threat Landscapes
-
批准号:RGPIN-2021-03141
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.75万
-
财政年份:2021
-
负责人:Alaca, Furkan
-
依托单位:
Securing User Authentication in Emerging Threat Landscapes
-
批准号:DGECR-2021-00125
-
项目类别:Discovery Launch Supplement
-
资助金额:$0.91万
-
财政年份:2021
-
负责人:Alaca, Furkan
-
依托单位:
Intelligent and Adaptive Resource Allocation in Wireless Cellular Networks
-
批准号:427671-2012
-
项目类别:Alexander Graham Bell Canada Graduate Scholarships - Doctoral
-
资助金额:$2.55万
-
财政年份:2014
-
负责人:Alaca, Furkan
-
依托单位:
Intelligent and Adaptive Resource Allocation in Wireless Cellular Networks
-
批准号:427671-2012
-
项目类别:Alexander Graham Bell Canada Graduate Scholarships - Doctoral
-
资助金额:$2.55万
-
财政年份:2013
-
负责人:Alaca, Furkan
-
依托单位:
Intelligent and Adaptive Resource Allocation in Wireless Cellular Networks
-
批准号:427671-2012
-
项目类别:Alexander Graham Bell Canada Graduate Scholarships - Doctoral
-
资助金额:$2.55万
-
财政年份:2012
-
负责人:Alaca, Furkan
-
依托单位:
optimizing sensor networks to collect environmental data
-
批准号:394233-2010
-
项目类别:Alexander Graham Bell Canada Graduate Scholarships - Master's
-
资助金额:$1.27万
-
财政年份:2010
-
负责人:Alaca, Furkan
-
依托单位:
Radio resource management for next generation wireless cellular networks
-
批准号:400479-2010
-
项目类别:University Undergraduate Student Research Awards
-
资助金额:$0.33万
-
财政年份:2010
-
负责人:Alaca, Furkan
-
依托单位:
Constellation rearrangement in cooperative relay networks
-
批准号:383415-2009
-
项目类别:University Undergraduate Student Research Awards
-
资助金额:$0.33万
-
财政年份:2009
-
负责人:Alaca, Furkan
-
依托单位:
Radio resource management in emerging wireless multihop networks
-
批准号:367670-2008
-
项目类别:University Undergraduate Student Research Awards
-
资助金额:$0.33万
-
财政年份:2008
-
负责人:Alaca, Furkan
-
依托单位:
海外基金