论文标题
在基于OTP的两个和一半因素身份验证中检测和防止凭证滥用,用于利用基于区块链的身份管理的集中式服务
Detecting and Preventing Credential Misuse in OTP-Based Two and Half Factor Authentication Toward Centralized Services Utilizing Blockchain-Based Identity Management
论文作者
论文摘要
这项工作着重于检测和预防被盗和滥用的秘密(例如私钥),以实现集中服务的身份验证。我们根据基于基于区块链的两因素身份验证方案SMARTOTPS提出了解决此类问题的解决方案,我们为我们的目的修改,并在针对集中式服务提供商的两个和半因子身份验证中使用。我们提出的解决方案由四个实体组成,它们共同互动以确保身份验证:(1)用户,(2)身份验证者,(3)服务提供商以及(4)智能合约。在我们解决方案的两个半因素中,第一个因素代表了私钥,第二个半因素代表了一次性密码(OTP)及其前体,在该密码中,从crotatecroptosporment上安全的哈希(Secrography Securetical Securetical Securething Hashhing)从前体(又称图像前)获得了OTP。我们描述了引导方法以及身份验证程序的协议。我们对解决方案进行了安全分析,在该解决方案的主要攻击者模型之上,从客户那里窃取了秘密,我们分析了中间攻击和与客户的恶意软件篡改。在被盗的凭据的情况下,我们表明我们的解决方案使用户能够立即检测出攻击发生,并通过新的凭据重新定位。
This work focuses on the problem of detection and prevention of stolen and misused secrets (such as private keys) for authentication toward centralized services. We propose a solution for such a problem based on the blockchain-based two-factor authentication scheme SmartOTPs, which we modify for our purposes and utilize in the setting of two and half-factor authentication against a centralized service provider. Our proposed solution consists of four entities that interact together to ensure authentication: (1) the user, (2) the authenticator, (3) the service provider, and (4) the smart contract. Out of two and a half factors of our solution, the first factor stands for the private key, and the second and a half factor stands for one-time passwords (OTPs) and their precursors, where OTPs are obtained from the precursors (a.k.a., pre-images) by cryptographically secure hashing. We describe the protocol for bootstrapping our approach as well as the authentication procedure. We make the security analysis of our solution, where on top of the main attacker model that steals secrets from the client, we analyze man-in-the-middle attacks and malware tampering with the client. In the case of stolen credentials, we show that our solution enables the user to immediately detect the attack occurrence and proceed to re-initialization with fresh credentials.