DocumentCode
3577859
Title
Mutual zero-knowledge authentication based on virtual passwords per session (MAVPS)
Author
Asimi, Younes ; Amghar, Abdellah ; Asimi, Ahmed ; Sadqi, Yassine
Author_Institution
Controle d´Acces et Modelisation (SCCAM) Depts. of Math., Ibn Zohr Univ., Agadir, Morocco
fYear
2014
Firstpage
231
Lastpage
236
Abstract
Currently, web applications have become more relevant to citizens´ privacy. The heightened security in this public space is not yet assured which always creates problems of mutual trust and validity of information. In fact, the majority of web applications are insecure, despite the widespread usage of SSL protocol ([13], [18]), which is, recently, the only protocol for securing the communication between the client and server. The objective of this paper is to propose a new mutual authentication system based on virtual passwords per session (MAVPS), as an alternative of SSL protocol. The aim is to introduce an authentication system able to the zero knowledge users´ identification ensuring untraceability, portability, unpredictability, integrity and reusability of their authentication settings. The users´ authentication is founded on the symmetric encryption by a virtual password regenerated in each session. The interest is to assure the integrity and the confidentiality of the private data exchanged between the client and server. This strengthen authentication process aims to create a secure communication channel able to protect our system against any information leak and to supply better defense against the various types of attacks.
Keywords
Internet; cryptography; data privacy; message authentication; MAVPS; SSL protocol; mutual trust; mutual zero-knowledge authentication based on virtual passwords per session; private data exchange; secure communication channel; symmetric encryption; virtual password; Browsers; Complexity theory; Cryptography; Lead; Nickel; Servers; Mutual authentication; Private data exchanged; Secure communication channel and Attacks; Virtual password per session; Web applications; Zero-knowledge users´ identification;
fLanguage
English
Publisher
ieee
Conference_Titel
Complex Systems (WCCS), 2014 Second World Conference on
Print_ISBN
978-1-4799-4648-8
Type
conf
DOI
10.1109/ICoCS.2014.7060878
Filename
7060878
Link To Document