期刊文献+
共找到2篇文章
< 1 >
每页显示 20 50 100
Security Analysis of an Attractive Online Authentication Standard:FIDO UAF Protocol 被引量:1
1
作者 Kexin Hu Zhenfeng Zhang 《China Communications》 SCIE CSCD 2016年第12期189-198,共10页
FIDO(Fast IDentity Online) Alliance proposed a set of standard in 2014 for change the nature of online authentication. By now, it has drawn attention from many companies, including Google, VISA, Intel etc. In this pap... FIDO(Fast IDentity Online) Alliance proposed a set of standard in 2014 for change the nature of online authentication. By now, it has drawn attention from many companies, including Google, VISA, Intel etc. In this paper, we analyze the FIDO UAF(Universal Authentication Framework) Protocol, one of the two sets of specifications in the standard. We first present protocols' cryptographic abstractions for the registration and authentication protocols of the FIDO UAF. According to the abstractions, we discuss on selected security goals presented in the standard to study UAF security properties. We also propose three attacks, which the first two are based on an assumption that an attacker can corrupt the software installed on the user device, and the third is based on two users sharing a FIDO roaming authenticator. The results of the attacks are to impersonate the legitimate user to pass the online authentication. 展开更多
关键词 fido UAF protocol online authentication impersonation attack protocol’s cryptographic abstraction
下载PDF
基于FIDO协议的双向动态口令认证方案 被引量:5
2
作者 郭佳鑫 黄晓芳 徐蕾 《计算机工程与设计》 北大核心 2017年第11期2919-2924,共6页
为解决当前口令认证缺陷,提出一种基于FIDO协议的双向动态口令认证方案,采用软件令牌的方式实现。对当前动态口令方案进行分析,结合移动终端特点,设计一种基于移动终端的高效双向动态口令认证协议;研究FIDO协议特点,将FIDO协议与双向动... 为解决当前口令认证缺陷,提出一种基于FIDO协议的双向动态口令认证方案,采用软件令牌的方式实现。对当前动态口令方案进行分析,结合移动终端特点,设计一种基于移动终端的高效双向动态口令认证协议;研究FIDO协议特点,将FIDO协议与双向动态口令结合,实现本地生物认证,进一步加强用户和云服务安全。安全分析结果表明,该方案能够抵御多种网络攻击。 展开更多
关键词 动态口令 双向认证 在线快速认证协议 移动终端 云服务
下载PDF
上一页 1 下一页 到第
使用帮助 返回顶部