当前位置: X-MOL 学术IEEE Trans. Inform. Forensics Secur. › 论文详情
Our official English website, www.x-mol.net, welcomes your feedback! (Note: you will need to create a separate account there.)
Killing the Password and Preserving Privacy With Device-Centric and Attribute-Based Authentication
IEEE Transactions on Information Forensics and Security ( IF 6.3 ) Pub Date : 12-12-2019 , DOI: 10.1109/tifs.2019.2958763
Kostantinos Papadamou , Steven Gevers , Christos Xenakis , Michael Sirivianos , Savvas Zannettou , Bogdan Chifor , Sorin Teican , George Gugulea , Alberto Caponi , Annamaria Recupero , Claudio Pisa , Giuseppe Bianchi

Current authentication methods on the Web have serious weaknesses. First, services heavily rely on the traditional password paradigm, which diminishes the end-users' security and usability. Second, the lack of attribute-based authentication does not allow anonymity-preserving access to services. Third, users have multiple online accounts that often reflect distinct identity aspects. This makes proving combinations of identity attributes hard on the users. In this paper, we address these weaknesses by proposing a privacy-preserving architecture for device-centric and attribute-based authentication based on: 1) the seamless integration between usable/strong device-centric authentication methods and federated login solutions; 2) the separation of the concerns for Authorization, Authentication, Behavioral Authentication and Identification to facilitate incremental deployability, wide adoption and compliance with NIST assurance levels; and 3) a novel centralized component that allows end-users to perform identity profile and consent management, to prove combinations of fragmented identity aspects, and to perform account recovery in case of device loss. To the best of our knowledge, this is the first effort towards fusing the aforementioned techniques under an integrated architecture. This architecture effectively deems the password paradigm obsolete with minimal modification on the service provider's software stack.

中文翻译:


通过以设备为中心和基于属性的身份验证消除密码并保护隐私



当前网络上的身份验证方法存在严重缺陷。首先,服务严重依赖传统的密码范例,这降低了最终用户的安全性和可用性。其次,缺乏基于属性的身份验证不允许对服务进行匿名访问。第三,用户拥有多个在线帐户,这些帐户通常反映不同的身份方面。这使得证明身份属性的组合对用户来说变得困难。在本文中,我们通过提出一种以设备为中心和基于属性的身份验证的隐私保护架构来解决这些弱点,该架构基于:1)可用/强大的以设备为中心的身份验证方法与联合登录解决方案之间的无缝集成; 2) 分离授权、身份验证、行为身份验证和识别的关注点,以促进增量部署、广泛采用和符合 NIST 保证级别; 3)一种新颖的集中式组件,允许最终用户执行身份配置文件和同意管理,证明碎片身份方面的组合,并在设备丢失时执行帐户恢复。据我们所知,这是在集成架构下融合上述技术的首次尝试。这种架构实际上认为密码范式已经过时,只需对服务提供商的软件堆栈进行最少的修改。
更新日期:2024-08-22
down
wechat
bug