DocumentCode
1836531
Title
DPAC: A Reuse-Oriented Password Authentication Framework for Improving Password Security
Author
Wang, Hua ; Guo, Yao ; Chen, Xiangqun
Author_Institution
Sch. of EECS, Peking Univ., Peking
fYear
2008
fDate
3-5 Dec. 2008
Firstpage
475
Lastpage
478
Abstract
Traditionally, password authentication is distributed to each application, so developers have to take counter measures by themselves to defend passwords against various threats. This requires a great amount of effort, a lot of which is repetitive. The high cost poses a potential hindrance to the adoption of countermeasures. This paper proposes a new reuse-oriented password authentication framework, called desktop password authentication center (DPAC), to reuse counter-measures among applications, thus reducing the cost of defending passwords against threats. In DPAC, we move the task of authentication, as well as the responsibility for protecting passwords, from applications to a dedicated authentication center (AuthCenter), so that countermeasures only need to be taken in AuthCenter and afterwards are reused by all applications. This solution can eliminate a lot of repetitive work and reduce the cost significantly. We demonstrate the feasibility of DPAC by implementing a prototype, in which we migrate the widely used OpenSSH to DPAC and implement two example countermeasures.
Keywords
message authentication; OpenSSH; dedicated authentication center; desktop password authentication center; password security; reuse-oriented password authentication framework; Authentication; Costs; Educational technology; Laboratories; Libraries; Network servers; Protection; Prototypes; Security; Systems engineering and theory; DPAC; Password Authentication; Reuse; Security;
fLanguage
English
Publisher
ieee
Conference_Titel
High Assurance Systems Engineering Symposium, 2008. HASE 2008. 11th IEEE
Conference_Location
Nanjing
ISSN
1530-2059
Print_ISBN
978-0-7695-3482-4
Type
conf
DOI
10.1109/HASE.2008.22
Filename
4708910
Link To Document