DocumentCode :
2238035
Title :
An Online User Authentication Scheme for Web-Based services
Author :
Sheng, Yu ; Lu, Zhu
Author_Institution :
Inst. of Electron. Technol., Inf. Eng. Univ., Zhengzhou
Volume :
2
fYear :
2008
fDate :
19-19 Dec. 2008
Firstpage :
173
Lastpage :
176
Abstract :
Online user authentication using secure protocol is required by most web-based services. User authentication is mostly carried out by sending a pair of username and password to the server, since most users have not a certificate. Some attacks just rely on this fact, such as phishing attacks. In the paper, we discuss the issue of online user authentication and propose a method for online user authentication employing trusted computing technology. We describe a browser extension scheme, which transparently produces a certificate for each user, improving web authentication security and defending against password phishing and other attacks. Since the scheme combines the password entered by the user, the password associated with private key protected by trusted platform module, and user certificate provided by trusted computing platform, thieving only the password at web will not have an affect on user security. And no changes on the server side are required in the scheme. The proposed approach could be proved to protect against phishing attacks.
Keywords :
Web services; private key cryptography; Web-based services; browser extension; online user authentication; phishing attacks; private key; secure protocol; Authentication; Computer crime; Electronic mail; Information management; Protection; Protocols; Public key; Security; Seminars; Web server;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Business and Information Management, 2008. ISBIM '08. International Seminar on
Conference_Location :
Wuhan
Print_ISBN :
978-0-7695-3560-9
Type :
conf
DOI :
10.1109/ISBIM.2008.217
Filename :
5116449
Link To Document :
بازگشت