DocumentCode
2238035
Title
An Online User Authentication Scheme for Web-Based services
Author
Sheng, Yu ; Lu, Zhu
Author_Institution
Inst. of Electron. Technol., Inf. Eng. Univ., Zhengzhou
Volume
2
fYear
2008
fDate
19-19 Dec. 2008
Firstpage
173
Lastpage
176
Abstract
Online user authentication using secure protocol is required by most web-based services. User authentication is mostly carried out by sending a pair of username and password to the server, since most users have not a certificate. Some attacks just rely on this fact, such as phishing attacks. In the paper, we discuss the issue of online user authentication and propose a method for online user authentication employing trusted computing technology. We describe a browser extension scheme, which transparently produces a certificate for each user, improving web authentication security and defending against password phishing and other attacks. Since the scheme combines the password entered by the user, the password associated with private key protected by trusted platform module, and user certificate provided by trusted computing platform, thieving only the password at web will not have an affect on user security. And no changes on the server side are required in the scheme. The proposed approach could be proved to protect against phishing attacks.
Keywords
Web services; private key cryptography; Web-based services; browser extension; online user authentication; phishing attacks; private key; secure protocol; Authentication; Computer crime; Electronic mail; Information management; Protection; Protocols; Public key; Security; Seminars; Web server;
fLanguage
English
Publisher
ieee
Conference_Titel
Business and Information Management, 2008. ISBIM '08. International Seminar on
Conference_Location
Wuhan
Print_ISBN
978-0-7695-3560-9
Type
conf
DOI
10.1109/ISBIM.2008.217
Filename
5116449
Link To Document