首页> 外文会议>IEEE Symposium on Security and Privacy >True2F: Backdoor-Resistant Authentication Tokens
【24h】

True2F: Backdoor-Resistant Authentication Tokens

机译:True2F:防后门身份验证令牌

获取原文

摘要

We present True2F, a system for second-factor authentication that provides the benefits of conventional authentication tokens in the face of phishing and software compromise, while also providing strong protection against token faults and backdoors. To do so, we develop new lightweight two-party protocols for generating cryptographic keys and ECDSA signatures, and we implement new privacy defenses to prevent cross-origin token-fingerprinting attacks. To facilitate real-world deployment, our system is backwards-compatible with today's U2F-enabled web services and runs on commodity hardware tokens after a firmware modification. A True2F-protected authentication takes just 57ms to complete on the token, compared with 23ms for unprotected U2F.
机译:我们介绍了True2F,这是一种用于二次身份验证的系统,可以在面对网络钓鱼和软件入侵时提供常规身份验证令牌的好处,同时还提供了针对令牌故障和后门的强大保护。为此,我们开发了新的轻量级两方协议来生成加密密钥和ECDSA签名,并且我们实施了新的隐私保护措施以防止跨域令牌指纹攻击。为了促进实际部署,我们的系统与当今启用了U2F的Web服务向后兼容,并在固件修改后以商品硬件令牌运行。受True2F保护的身份验证仅需57毫秒即可完成令牌,而未受保护的U2F则需要23毫秒。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号