首页> 外文会议>European Workshop on Security in Ad-hoc and Sensor Networks(ESAS 2004); 20040806; Heidelberg(DE) >Securely Propagating Authentication in an Ensemble of Personal Devices Using Single Sign-on
【24h】

Securely Propagating Authentication in an Ensemble of Personal Devices Using Single Sign-on

机译:使用单点登录在一组个人设备中安全地传播身份验证

获取原文
获取原文并翻译 | 示例

摘要

More and more, people will continuously be using ubiquitously available networked computational devices as they go about their lives: small personal devices that they carry, appliances that they find in their surroundings, and servers in remote data centers. Some of the data exchanged by these devices will be private and should be protected. Normally to protect data, users would need to authenticate themselves with a device by signing on to it. However it will be physically impossible to sign onto devices that have limited or no user interface and even if they all had a sufficient user interface it will be an intolerable burden to have to sign on to each of many devices, particularly as the membership of the ensemble of devices continuously changes with the user's movements. Making authentication in this environment more difficult is the fact that these devices are usually connected in a personal area network that is neither secure nor reliable and uses a broadcast medium for communication. In this paper, we present a simple easy-to-use scheme that allows users to sign on to a single device and enable the rest of the devices connected in the personal area network automatically without requiring a central server or synchronized clocks. As well as being simple for the user, our solution is designed not only to prevent commonly used attacks like replay and man-in-the-middle but also to protect the user's data even if the devices are lost or stolen.
机译:人们越来越多地会在生活中继续使用无处不在的网络计算设备:他们携带的小型个人设备,在周围环境中找到的设备以及远程数据中心中的服务器。这些设备交换的某些数据将是私有的,应受到保护。通常,为了保护数据,用户需要通过登录设备来对自己进行身份验证。但是,在物理上不可能登录到具有有限用户界面或没有用户界面的设备,即使它们都具有足够的用户界面,必须登录许多设备中的每一个设备也将是无法忍受的负担,尤其是作为用户的成员身份时设备的整体随着用户的移动而不断变化。这些设备通常连接在既不安全也不可靠并且使用广播介质进行通信的个人区域网络中,这使在这种环境下进行身份验证更加困难。在本文中,我们提出了一种简单易用的方案,该方案允许用户登录到单个设备,并自动启用连接在个人局域网中的其余设备,而无需中央服务器或同步时钟。我们的解决方案不仅对用户简单,而且不仅可以防止诸如重放和中间人之类的常用攻击,而且即使设备丢失或被盗也可以保护用户的数据。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号