首页> 外文期刊>Journal of Information Recording >Hash-Based Password Authentication Protocol Against Phishing and Pharming Attacks
【24h】

Hash-Based Password Authentication Protocol Against Phishing and Pharming Attacks

机译:基于哈希的网络钓鱼和域名攻击密码认证协议

获取原文
获取原文并翻译 | 示例
           

摘要

Until now, although many researchers proposed a variety of authentication protocol to verify the identity of the clients, most of these protocols are inefficient and ineffective. Gouda et al. proposed an anti-phishing single password protocol, but it is vulnerable to pharming attacks. In this paper, we show that the protocol is insecure, and propose a hash-based password authentication protocol against phishing and pharming attacks. In the proposed protocol, the authentication tickets passed between clients and servers are secure because they are hash values which can be verified only by clients and servers. The authentication ticket is used only once, which ensures that the proposed protocol is secure against a variety of attacks such as replay, man-in-the-middle, phishing, and pharming. Because the proposed authentication protocol does not require encryption keys during the authentication phase, it is suitable for wireless and mobile communication systems.
机译:到目前为止,尽管许多研究人员提出了各种身份验证协议来验证客户端的身份,但是这些协议大多数还是无效的和无效的。 Gouda等。提出了一种反网络钓鱼的单密码协议,但它很容易受到欺骗攻击。在本文中,我们证明了该协议是不安全的,并提出了一种基于哈希的,针对网络钓鱼和欺骗攻击的密码认证协议。在提出的协议中,在客户端和服务器之间传递的身份验证票证是安全的,因为它们是只能由客户端和服务器验证的哈希值。身份验证票证仅使用一次,从而确保所提出的协议对各种攻击(例如重播,中间人,网络钓鱼和欺骗)都是安全的。由于建议的身份验证协议在身份验证阶段不需要加密密钥,因此适用于无线和移动通信系统。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号