当前位置: X-MOL 学术arXiv.cs.CR › 论文详情
Our official English website, www.x-mol.net, welcomes your feedback! (Note: you will need to create a separate account there.)
Killing the Password and Preserving Privacy with Device-Centric and Attribute-based Authentication
arXiv - CS - Cryptography and Security Pub Date : 2018-11-20 , DOI: arxiv-1811.08360
Kostantinos Papadamou and Savvas Zannettou and Bogdan Chifor and Sorin Teican and George Gugulea and Annamaria Recupero and Alberto Caponi and Claudio Pisa and Giuseppe Bianchi and Steven Gevers and Christos Xenakis and Michael Sirivianos

Current authentication methods on the Web have serious weaknesses. First, services heavily rely on the traditional password paradigm, which diminishes the end-users' security and usability. Second, the lack of attribute-based authentication does not allow anonymity-preserving access to services. Third, users have multiple online accounts that often reflect distinct identity aspects. This makes proving combinations of identity attributes hard on the users. In this paper, we address these weaknesses by proposing a privacy-preserving architecture for device-centric and attribute-based authentication based on: 1) the seamless integration between usable/strong device-centric authentication methods and federated login solutions; 2) the separation of the concerns for Authorization, Authentication, Behavioral Authentication and Identification to facilitate incremental deployability, wide adoption and compliance with NIST assurance levels; and 3) a novel centralized component that allows end-users to perform identity profile and consent management, to prove combinations of fragmented identity aspects, and to perform account recovery in case of device loss. To the best of our knowledge, this is the first effort towards fusing the aforementioned techniques under an integrated architecture. This architecture effectively deems the password paradigm obsolete with minimal modification on the service provider's software stack.

中文翻译:

通过以设备为中心和基于属性的身份验证杀死密码并保护隐私

当前 Web 上的身份验证方法存在严重的弱点。首先,服务严重依赖传统的密码范式,这降低了最终用户的安全性和可用性。其次,缺乏基于属性的身份验证不允许匿名访问服务。第三,用户拥有多个在线帐户,这些帐户通常反映了不同的身份方面。这使得用户难以证明身份属性的组合。在本文中,我们通过提出一种用于以设备为中心和基于属性的身份验证的隐私保护架构来解决这些弱点:1)可用/强大的以设备为中心的身份验证方法与联合登录解决方案之间的无缝集成;2) 授权、认证关注点的分离,行为认证和识别,以促进增量部署、广泛采用和符合 NIST 保证级别;3) 一种新颖的集中式组件,允许最终用户执行身份配置文件和同意管理,证明碎片身份方面的组合,并在设备丢失的情况下执行帐户恢复。据我们所知,这是在集成架构下融合上述技术的第一次努力。这种架构有效地认为密码范式已过时,只需对服务提供商的软件堆栈进行最少的修改。证明碎片身份方面的组合,并在设备丢失的情况下执行帐户恢复。据我们所知,这是在集成架构下融合上述技术的第一次努力。这种架构有效地认为密码范式已过时,只需对服务提供商的软件堆栈进行最少的修改。证明碎片身份方面的组合,并在设备丢失的情况下执行帐户恢复。据我们所知,这是在集成架构下融合上述技术的第一次努力。这种架构有效地认为密码范式已过时,只需对服务提供商的软件堆栈进行最少的修改。
更新日期:2020-01-17
down
wechat
bug