A Study on Document Password Management using the Trust-Chain Based SPT (Work-in-Progress)

Hyung-Jong Kim, Soyeon Park
{"title":"A Study on Document Password Management using the Trust-Chain Based SPT (Work-in-Progress)","authors":"Hyung-Jong Kim, Soyeon Park","doi":"10.1109/ICSSA45270.2018.00016","DOIUrl":null,"url":null,"abstract":"The password setting of the MS-Office document file is a representative security countermeasure which is commonly used. Especially in the SOHO (Small Office Home Office) company case, the password for the MS-Office document file could be the affordable and solitary solution for the document security. By setting the password of the document, the owner of the file can ensure the confidentiality and integrity of the content of the document file. However, there are issues in this simple security mechanism such as the dependency of the strength of passwords and the difficulty of the password management. In this work, we propose two mechanisms for overcoming these two issues by adding simple but effective mechanisms named the SPT (Secure Password Translation) and the chain of trust. The SPT generates passwords for the MS-Office document files and the generated password has enough strength that the government regulation requires. For the preserving the integrity of the passwords and software components, we propose the chain of trust. By using these mechanisms, SOHO companies can preserve the confidentiality and integrity of the document files. In addition, the implementation of the trust-chain based SPT is easy and affordable to deploy. The contribution of this work is in proposing the design of software for managing passwords of the MS-Office document using SPT and the chain of trust.","PeriodicalId":223442,"journal":{"name":"2018 International Conference on Software Security and Assurance (ICSSA)","volume":"1 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2018-07-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2018 International Conference on Software Security and Assurance (ICSSA)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICSSA45270.2018.00016","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 1

Abstract

The password setting of the MS-Office document file is a representative security countermeasure which is commonly used. Especially in the SOHO (Small Office Home Office) company case, the password for the MS-Office document file could be the affordable and solitary solution for the document security. By setting the password of the document, the owner of the file can ensure the confidentiality and integrity of the content of the document file. However, there are issues in this simple security mechanism such as the dependency of the strength of passwords and the difficulty of the password management. In this work, we propose two mechanisms for overcoming these two issues by adding simple but effective mechanisms named the SPT (Secure Password Translation) and the chain of trust. The SPT generates passwords for the MS-Office document files and the generated password has enough strength that the government regulation requires. For the preserving the integrity of the passwords and software components, we propose the chain of trust. By using these mechanisms, SOHO companies can preserve the confidentiality and integrity of the document files. In addition, the implementation of the trust-chain based SPT is easy and affordable to deploy. The contribution of this work is in proposing the design of software for managing passwords of the MS-Office document using SPT and the chain of trust.
基于信任链的SPT文档密码管理研究
MS-Office文档文件的密码设置是一种典型的常用安全对策。特别是在SOHO(小型办公室家庭办公室)公司的情况下,MS-Office文档文件的密码可能是一种经济实惠的文档安全解决方案。通过设置文档的密码,文件的所有者可以保证文档文件内容的保密性和完整性。然而,这种简单的安全机制存在着密码强度的依赖性和密码管理的难度等问题。在这项工作中,我们提出了两种机制来克服这两个问题,通过添加简单而有效的机制,称为SPT(安全密码转换)和信任链。SPT为MS-Office文档文件生成密码,生成的密码具有足够的政府监管要求的强度。为了保证密码和软件组件的完整性,我们提出了信任链。通过使用这些机制,SOHO公司可以保持文档文件的机密性和完整性。此外,基于信任链的SPT的实现易于部署且负担得起。本文的贡献在于提出了一种基于SPT和信任链的MS-Office文档密码管理软件的设计方案。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信