Virtual password using random linear functions for on-line services, ATM machines, and pervasive computing

被引:22
作者
Lei, Ming [1 ]
Xiao, Yang [1 ]
Vrbsky, Susan V. [1 ]
Li, Chung-Chih [2 ]
机构
[1] Univ Alabama, Dept Comp Sci, Tuscaloosa, AL 35487 USA
[2] Illinois State Univ, Sch Informat Technol, Normal, IL 61790 USA
基金
美国国家科学基金会;
关键词
Security; Password; On-line services; User ID; ATM machines;
D O I
10.1016/j.comcom.2008.05.005
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
People enjoy the convenience of on-line services, Automated Teller Machines (ATMs), and pervasive computing, but online environments, ATMs, and pervasive computing may bring many risks. In this paper, we discuss how to prevent users' passwords from being stolen by adversaries. We propose a virtual password concept involving a small amount of human computing to secure users' passwords in on-line environments, ATMs, and pervasive computing. We adopt user-determined randomized linear generation functions to secure users' passwords based on the fact that a server has more information than any adversary does. We analyze how the proposed schemes defend against phishing, key logger, and shoulder-surfing attacks. To the best of our knowledge, our virtual password mechanism is the first one which is able to defend against all three attacks together. (C) 2008 Elsevier B.V. All rights reserved.
引用
收藏
页码:4367 / 4375
页数:9
相关论文
共 29 条
[1]  
ABADI M, 1997, Patent No. 61411997760
[2]  
[Anonymous], 1998, Learning for Text Categorization
[3]  
ATENIESE G, 2005, P 12 ANN NETW DISTR
[4]  
Brennen V. A., 2004, CRYPTOGRAPHY DICT, V2005
[5]  
DAMIANI E, 2004, P 13 INT WORLD WID W, P358
[6]  
DIERKS T, 1999, 2246 IETF RFC
[7]  
GABBER E, 1999, ACM T INFORM SYST, V2, P390
[8]  
GABER E, 1997, LNCS, V1318
[9]  
HERLEY C, P S US PRIV SEC SOUP
[10]  
Herzberg A., 2004, Report 2004/155