Cookie-Based Virtual Password Authentication Protocol

被引:1
作者
Sood, Sandeep K. [1 ]
机构
[1] GNDU, Dept Comp Sci & Engn, Reg Campus, Gurdaspur, India
来源
INFORMATION SECURITY JOURNAL | 2011年 / 20卷 / 02期
关键词
cookies; hyper text transfer protocol; virtual password; secure socket layer; online dictionary attacks;
D O I
10.1080/19393555.2011.560924
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The password is the most common technique used to authenticate Web users. Password-based authentication protocols are susceptible to automated dictionary attacks because most passwords are chosen by users from their personal domain. In this paper, we propose a cookie-based virtual password authentication protocol that preserves the advantages of conventional password authentication while simultaneously increasing the efforts required for online dictionary attacks. The Web server stores the cookie on the user's machine if the legitimate user authenticates to the Web server. Thereafter, the legitimate user can easily authenticate to the Web server from a machine that contains the cookie. However, the legitimate user requires some additional computational efforts during login from a machine that does not contain the cookie. The computation efforts required from the attacker during login to the Web server increases exponentially with each login failure. The user generated virtual password is different for the same user in different sessions of Secure Socket Layer (SSL) protocol. The concept used in this paper is to combine traditional password authentication with a challenge that is easy to answer by the legitimate user but computational cost increases for the attacker with each login failure. Therefore, even the automated programs cannot launch online dictionary attacks on the proposed protocol. This protocol provides good security against different types of attacks launched by the attacker. The proposed protocol is easy to implement and removes some of the drawbacks of earlier proposed password-based authentication protocols.
引用
收藏
页码:100 / 111
页数:12
相关论文
共 19 条
[1]   A lightweight approach to authenticated web caching [J].
Blundo, C ;
Cimato, S ;
De Prisco, R .
2005 SYMPOSIUM ON APPLICATIONS AND THE INTERNET, PROCEEDINGS, 2005, :157-163
[2]  
Freier A., 1996, SSL PROTOCOL VERSION
[3]  
Fu K., 2001, P ASME INT MECH ENG, P1
[4]   A new protocol to counter online dictionary attacks [J].
Goyal, V ;
Kumar, V ;
Singh, M ;
Abraham, A ;
Sanyal, S .
COMPUTERS & SECURITY, 2006, 25 (02) :114-120
[5]   Cache cookies for browser authentication - (Extended abstract) [J].
Juels, Ari ;
Jakobsson, Markus ;
Jagatic, Tom N. .
2006 IEEE Symposium on Security and Privacy, Proceedings, 2006, :301-305
[6]  
KARLOF C, 2007, ACM C COMP COMM SEC, P58
[7]   Risks of the Passport single signon protocol [J].
Kormann, DP ;
Rubin, AD .
COMPUTER NETWORKS, 2000, 33 (1-6) :51-58
[8]   Virtual password using random linear functions for on-line services, ATM machines, and pervasive computing [J].
Lei, Ming ;
Xiao, Yang ;
Vrbsky, Susan V. ;
Li, Chung-Chih .
COMPUTER COMMUNICATIONS, 2008, 31 (18) :4367-4375
[9]   A secure cookie protocol [J].
Liu, AX ;
Kovacs, JM ;
Huang, CT ;
Gouda, MG .
ICCCN 2005: 14TH INTERNATIONAL CONFERENCE ON COMPUTER COMMUNICATIONS AND NETWORKS, PROCEEDINGS, 2005, :333-338
[10]   Secure cookies on the Web [J].
Park, JS ;
Sandhu, R .
IEEE INTERNET COMPUTING, 2000, 4 (04) :36-44