• DocumentCode
    2238035
  • Title

    An Online User Authentication Scheme for Web-Based services

  • Author

    Sheng, Yu ; Lu, Zhu

  • Author_Institution
    Inst. of Electron. Technol., Inf. Eng. Univ., Zhengzhou
  • Volume
    2
  • fYear
    2008
  • fDate
    19-19 Dec. 2008
  • Firstpage
    173
  • Lastpage
    176
  • Abstract
    Online user authentication using secure protocol is required by most web-based services. User authentication is mostly carried out by sending a pair of username and password to the server, since most users have not a certificate. Some attacks just rely on this fact, such as phishing attacks. In the paper, we discuss the issue of online user authentication and propose a method for online user authentication employing trusted computing technology. We describe a browser extension scheme, which transparently produces a certificate for each user, improving web authentication security and defending against password phishing and other attacks. Since the scheme combines the password entered by the user, the password associated with private key protected by trusted platform module, and user certificate provided by trusted computing platform, thieving only the password at web will not have an affect on user security. And no changes on the server side are required in the scheme. The proposed approach could be proved to protect against phishing attacks.
  • Keywords
    Web services; private key cryptography; Web-based services; browser extension; online user authentication; phishing attacks; private key; secure protocol; Authentication; Computer crime; Electronic mail; Information management; Protection; Protocols; Public key; Security; Seminars; Web server;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Business and Information Management, 2008. ISBIM '08. International Seminar on
  • Conference_Location
    Wuhan
  • Print_ISBN
    978-0-7695-3560-9
  • Type

    conf

  • DOI
    10.1109/ISBIM.2008.217
  • Filename
    5116449