题名

Inverse Cookie-based Virtual Password Authentication Protocol

DOI

10.6633/IJNS.201109.13(2).05

作者

Sandeep Kumar Sood;Anil K. Sarje;Kuldip Singh

关键词

Cookies ; hyper text transfer protocol ; online dictionary attacks ; secure socket layer ; virtual password

期刊名称

International Journal of Network Security

卷期/出版年月

13卷2期(2011 / 09 / 01)

页次

98 - 108

内容语文

英文

英文摘要

Password is the most commonly used authentication technique to authenticate the users on the web. Password based authentication protocols are susceptible to dictionary attacks by means of automated programs because most of the user chosen passwords are limited to the user's personal domain. In this paper, we propose an inverse cookie based virtual password authentication protocol that preserves the advantages of basic password authentication and simultaneously increasing the efforts required for online dictionary attacks. The Web server stores the cookie on the client's computer when the client has not submitted correct identity and password for its authentication to the Web server. The legitimate client can easily authenticate itself to the Web server from any computer irrespective of whether that computer contains cookie or not. However, the computational efforts required from the attacker during login on to the Web server increases with each login failure. The client generated virtual password is different for the same user in different sessions of Secure Socket Layer (SSL) protocol. The concept used in this paper is to combine traditional password authentication with a challenge that is easy to answer by the legitimate client and the computational cost of authentication increases for the attacker with each login failure. Therefore, even the automated programs can not launch online dictionary attacks on the proposed protocol. This protocol provides better protection against different types of attacks launched by the attacker. The proposed protocol is easy to implement and it removes some of the deficiencies of previously suggested password based authentication protocols.

主题分类 基礎與應用科學 > 資訊科學
被引用次数
  1. 張峻豪(2017)。基於單晶片微電腦之感應馬達PID模糊速度控制。中原大學電機工程學系學位論文。2017。1-40。 
  2. 許銘軒(2016)。功率消耗與測試墊限制下之三維積體電路測試排程問題研究。中原大學電子工程學系學位論文。2016。1-66。