{"title":"Save Our Passwords","authors":"M. Boonk, Ronald Petrlic, Christoph Sorge","doi":"10.1109/Trustcom.2015.449","DOIUrl":null,"url":null,"abstract":"Passwords, despite the problems they entail, are still the most common method of user authentication-mainly due to convenience. We present an approach that aims at keeping passwords as an authentication mechanisms while significantly improving their practical security. We store passwords on smartcards -- which is not new -- , but the novelty of our approach is that we perform user authentication with those securely stored passwords between the smartcard and the server, without requiring any changes on the server side. We show the results of our implementation and provide our TLS handshake implementation on a smartcard for the community.","PeriodicalId":277092,"journal":{"name":"2015 IEEE Trustcom/BigDataSE/ISPA","volume":"32 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2015-08-20","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2015 IEEE Trustcom/BigDataSE/ISPA","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/Trustcom.2015.449","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0
Abstract
Passwords, despite the problems they entail, are still the most common method of user authentication-mainly due to convenience. We present an approach that aims at keeping passwords as an authentication mechanisms while significantly improving their practical security. We store passwords on smartcards -- which is not new -- , but the novelty of our approach is that we perform user authentication with those securely stored passwords between the smartcard and the server, without requiring any changes on the server side. We show the results of our implementation and provide our TLS handshake implementation on a smartcard for the community.