论文标题
一种新颖的两因素蜂蜜身份验证机制
A novel Two-Factor HoneyToken Authentication Mechanism
论文作者
论文摘要
大多数系统依赖于密码的用户身份验证,但是密码具有许多弱点和广泛的使用,无论其加密形式如何,都可以轻松引起严重的安全问题。用户保留了不同帐户的密码,管理员切勿检查密码文件是否可能导致成功破解,并且缺乏有关常规密码更换的紧密安全策略是需要解决的一些问题。拟议的研究工作旨在增强这种安全机制,防止渗透,密码盗窃以及试图闯入攻击计算系统。选定的解决方案方法是双重的;它实施了两因素身份验证方案,以防止未经授权的访问,并伴随着Honeyword原则,以检测损坏或被盗的令牌。可以使用QR码和手机将两者集成到任何平台或Web应用程序中。
The majority of systems rely on user authentication on passwords, but passwords have so many weaknesses and widespread use that easily raise significant security concerns, regardless of their encrypted form. Users hold the same password for different accounts, administrators never check password files for flaws that might lead to a successful cracking, and the lack of a tight security policy regarding regular password replacement are a few problems that need to be addressed. The proposed research work aims at enhancing this security mechanism, prevent penetrations, password theft, and attempted break-ins towards securing computing systems. The selected solution approach is two-folded; it implements a two-factor authentication scheme to prevent unauthorized access, accompanied by Honeyword principles to detect corrupted or stolen tokens. Both can be integrated into any platform or web application with the use of QR codes and a mobile phone.