多维:具有文件内容的用户和基于服务器状态的云端安全文件操作认证

Jims Marchang, Jing Wang, Abayomi Otebolaku, Timibloudi S. Enamamu, Daniel Porter, Benjamin Sanders
{"title":"多维:具有文件内容的用户和基于服务器状态的云端安全文件操作认证","authors":"Jims Marchang, Jing Wang, Abayomi Otebolaku, Timibloudi S. Enamamu, Daniel Porter, Benjamin Sanders","doi":"10.32474/CTCSA.2019.01.000121","DOIUrl":null,"url":null,"abstract":"The popularity of data storage in cloud servers is getting more and more favoured in recent times. Its ease of storage, availability and synchronization of personalized cloud file storage using client applications made cloud storage more popular than ever. In cloud storage system, using a basic authentication method like username and password are still one of the most popular forms of authentication. However, the security ensure by such traditional authentication method is weak and vulnerable because the user name and password can be compromised by intruders or the user account can be left open by forgetting to logoff in public computers, leading to exposure of information to unauthorised users and hackers. In recent years, using a two-factor authentication has become a trend throughout network-based cloud services, online banking system and any form of services that requires user authentication. Here, in this paper a second layer authentication in the form of session key is used to ensure the authenticity of the activities of the user after user’s web-based account is logged-in successfully. The interesting and the critical contribution in this paper is the way the session key is generated and delivers to the authentic user. The key is generated by using the hash value of the file content, file size, file last modified, pseudo-random generated by the server using CPU temperature, clock speed, system time, and network packet timings, and user based 8 digit random position selection from a 32 digit Hex to mitigate against the attacker while performing vital file activities which may lead to data lost or data destruction or when user’s credentials are compromised.","PeriodicalId":303860,"journal":{"name":"Current Trends in Computer Sciences & Applications","volume":"66 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2019-11-22","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"Multidimensional: User with File Content and Server’s Status Based Authentication for Secure File Operations in Cloud\",\"authors\":\"Jims Marchang, Jing Wang, Abayomi Otebolaku, Timibloudi S. Enamamu, Daniel Porter, Benjamin Sanders\",\"doi\":\"10.32474/CTCSA.2019.01.000121\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"The popularity of data storage in cloud servers is getting more and more favoured in recent times. Its ease of storage, availability and synchronization of personalized cloud file storage using client applications made cloud storage more popular than ever. In cloud storage system, using a basic authentication method like username and password are still one of the most popular forms of authentication. However, the security ensure by such traditional authentication method is weak and vulnerable because the user name and password can be compromised by intruders or the user account can be left open by forgetting to logoff in public computers, leading to exposure of information to unauthorised users and hackers. In recent years, using a two-factor authentication has become a trend throughout network-based cloud services, online banking system and any form of services that requires user authentication. Here, in this paper a second layer authentication in the form of session key is used to ensure the authenticity of the activities of the user after user’s web-based account is logged-in successfully. The interesting and the critical contribution in this paper is the way the session key is generated and delivers to the authentic user. The key is generated by using the hash value of the file content, file size, file last modified, pseudo-random generated by the server using CPU temperature, clock speed, system time, and network packet timings, and user based 8 digit random position selection from a 32 digit Hex to mitigate against the attacker while performing vital file activities which may lead to data lost or data destruction or when user’s credentials are compromised.\",\"PeriodicalId\":303860,\"journal\":{\"name\":\"Current Trends in Computer Sciences & Applications\",\"volume\":\"66 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2019-11-22\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Current Trends in Computer Sciences & Applications\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.32474/CTCSA.2019.01.000121\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Current Trends in Computer Sciences & Applications","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.32474/CTCSA.2019.01.000121","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

摘要

近年来,数据存储在云服务器上的普及越来越受到青睐。它易于存储,使用客户端应用程序的个性化云文件存储的可用性和同步性使云存储比以往任何时候都更受欢迎。在云存储系统中,使用用户名和密码等基本身份验证方法仍然是最流行的身份验证形式之一。然而,这种传统的认证方式所保证的安全性较弱,容易受到攻击,因为用户名和密码可能被入侵者泄露,或者在公共计算机上,用户帐户可能因忘记登录而被打开,导致信息暴露给未经授权的用户和黑客。近年来,在基于网络的云服务、网上银行系统和任何需要用户认证的服务中,使用双因素认证已经成为一种趋势。在此,本文采用会话密钥形式的第二层身份验证,在用户的web账户成功登录后,保证用户活动的真实性。本文中有趣且关键的贡献是生成会话密钥并将其传递给真实用户的方式。该密钥是通过使用文件内容、文件大小、文件最后修改的散列值、服务器使用CPU温度、时钟速度、系统时间和网络数据包时间生成的伪随机以及基于用户的32位十六进制的8位随机位置选择来生成的,以减轻攻击者在执行可能导致数据丢失或数据破坏的重要文件活动时的攻击,或者当用户的凭据受到损害时。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Multidimensional: User with File Content and Server’s Status Based Authentication for Secure File Operations in Cloud
The popularity of data storage in cloud servers is getting more and more favoured in recent times. Its ease of storage, availability and synchronization of personalized cloud file storage using client applications made cloud storage more popular than ever. In cloud storage system, using a basic authentication method like username and password are still one of the most popular forms of authentication. However, the security ensure by such traditional authentication method is weak and vulnerable because the user name and password can be compromised by intruders or the user account can be left open by forgetting to logoff in public computers, leading to exposure of information to unauthorised users and hackers. In recent years, using a two-factor authentication has become a trend throughout network-based cloud services, online banking system and any form of services that requires user authentication. Here, in this paper a second layer authentication in the form of session key is used to ensure the authenticity of the activities of the user after user’s web-based account is logged-in successfully. The interesting and the critical contribution in this paper is the way the session key is generated and delivers to the authentic user. The key is generated by using the hash value of the file content, file size, file last modified, pseudo-random generated by the server using CPU temperature, clock speed, system time, and network packet timings, and user based 8 digit random position selection from a 32 digit Hex to mitigate against the attacker while performing vital file activities which may lead to data lost or data destruction or when user’s credentials are compromised.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信