首页> 外文期刊>International Journal of Information Security >Secure modular password authentication for the web using channel bindings
【24h】

Secure modular password authentication for the web using channel bindings

机译:使用通道绑定对Web进行安全的模块化密码身份验证

获取原文
获取原文并翻译 | 示例
           

摘要

Secure protocols for password-based user authentication are well-studied in the cryptographic literature but have failed to see wide-spread adoption on the internet; most proposals to date require extensive modifications to the Transport Layer Security (TLS) protocol, making deployment challenging. Recently, a few modular designs have been proposed in which a cryptographically secure password-based mutual authentication protocol is run inside a confidential (but not necessarily authenticated) channel such as TLS; the password protocol is bound to the established channel to prevent active attacks. Such protocols are useful in practice for a variety of reasons: security no longer relies on users' ability to validate server certificates and can potentially be implemented with no modifications to the secure channel protocol library. We provide a systematic study of such authentication protocols. Building on recent advances in modeling TLS, we give a formal definition of the intended security goal, which we call password-authenticated and confidential channel establishment (PACCE). We show generically that combining a secure channel protocol, such as TLS, with a password authentication or password-authenticated key exchange protocol, where the two protocols are bound together using the transcript of the secure channel's handshake, the server's certificate, or the server's domain name, results in a secure PACCE protocol. Our prototypes based on TLS are available as a cross-platform client-side Firefox browser extension as well as an Android application and a server-side web application that can easily be installed on servers.
机译:在密码学文献中已对基于密码的用户身份验证的安全协议进行了充分研究,但未能在互联网上得到广泛采用。迄今为止,大多数提议都需要对传输层安全性(TLS)协议进行大量修改,这给部署带来了挑战。最近,有人提出了一些模块化设计,其中在诸如TLS之类的机密(但不一定经过身份验证)通道内运行基于密码安全的基于密码的双向身份验证协议。密码协议绑定到已建立的通道,以防止主动攻击。这样的协议在实践中由于多种原因而有用:安全不再依赖于用户验证服务器证书的能力,并且可以在不修改安全通道协议库的情况下实现。我们提供了有关此类身份验证协议的系统研究。基于TLS建模的最新进展,我们给出了预期的安全目标的正式定义,我们将其称为经过密码验证和机密的通道建立(PACCE)。我们总体上展示了将安全通道协议(例如TLS)与密码身份验证或经过密码身份验证的密钥交换协议结合在一起的情况,其中这两个协议是使用安全通道握手,服务器证书或服务器域的成绩单绑定在一起的名称,得到一个安全的PACCE协议。我们基于TLS的原型可作为跨平台客户端Firefox浏览器扩展以及可轻松安装在服务器上的Android应用程序和服务器端Web应用程序使用。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号