在线数据库的三层密码安全算法

Zubair Zaland, S. Bazai, Shahabzade Marjan, M. Ashraf
{"title":"在线数据库的三层密码安全算法","authors":"Zubair Zaland, S. Bazai, Shahabzade Marjan, M. Ashraf","doi":"10.1109/iisec54230.2021.9672434","DOIUrl":null,"url":null,"abstract":"Password security is a significant issue for any authenticating process, and different researchers in the past have proposed techniques such as hashing, salting, honeywords to make the process most secured. We provide a self-guaranteed secure program and its access methods to mitigate the risk of illegal attacks like DDoS. This method ensures the security of a program by giving method level security that bolsters the further implemented security measures. A step-up approach is implementing the access security measures that protect against SQL injection and script attacks. Lucubration of various papers suggests that most systems are compromised at the storage of login credentials. Our solution ensures the security of such measures by obscurity. By using multiple layers of additional security procedures before storing the data decreases the risk of break-in exponentially. Our attempt to securely store passwords includes salting the passwords, encrypting them, and finally hashing them so that no patterns are visible. This paper presents a new method that involves SQLi prevention, encrypting, salting and then hashing the password. The SALT is generated dynamically using two parameters, one of which is unique, and the Salt is not stored in the database.","PeriodicalId":344273,"journal":{"name":"2021 2nd International Informatics and Software Engineering Conference (IISEC)","volume":"294 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2021-12-16","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":"{\"title\":\"Three-Tier Password Security Algorithm for Online Databases\",\"authors\":\"Zubair Zaland, S. Bazai, Shahabzade Marjan, M. Ashraf\",\"doi\":\"10.1109/iisec54230.2021.9672434\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Password security is a significant issue for any authenticating process, and different researchers in the past have proposed techniques such as hashing, salting, honeywords to make the process most secured. We provide a self-guaranteed secure program and its access methods to mitigate the risk of illegal attacks like DDoS. This method ensures the security of a program by giving method level security that bolsters the further implemented security measures. A step-up approach is implementing the access security measures that protect against SQL injection and script attacks. Lucubration of various papers suggests that most systems are compromised at the storage of login credentials. Our solution ensures the security of such measures by obscurity. By using multiple layers of additional security procedures before storing the data decreases the risk of break-in exponentially. Our attempt to securely store passwords includes salting the passwords, encrypting them, and finally hashing them so that no patterns are visible. This paper presents a new method that involves SQLi prevention, encrypting, salting and then hashing the password. The SALT is generated dynamically using two parameters, one of which is unique, and the Salt is not stored in the database.\",\"PeriodicalId\":344273,\"journal\":{\"name\":\"2021 2nd International Informatics and Software Engineering Conference (IISEC)\",\"volume\":\"294 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2021-12-16\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"1\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2021 2nd International Informatics and Software Engineering Conference (IISEC)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/iisec54230.2021.9672434\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2021 2nd International Informatics and Software Engineering Conference (IISEC)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/iisec54230.2021.9672434","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 1

摘要

对于任何身份验证过程来说,密码安全性都是一个重要的问题,过去不同的研究人员提出了诸如哈希、盐化、蜜糖等技术来提高过程的安全性。我们提供自我保证的安全程序及其访问方法,以降低DDoS等非法攻击的风险。该方法通过提供支持进一步实现的安全措施的方法级安全性来确保程序的安全性。一种升级的方法是实现访问安全措施,防止SQL注入和脚本攻击。各种论文的研究表明,大多数系统都是在登录凭证的存储上受到损害的。我们的解决方案通过隐藏来确保这些措施的安全性。通过在存储数据之前使用多层额外的安全程序,以指数方式降低了入侵的风险。我们试图安全地存储密码,包括对密码进行腌制、加密,最后对它们进行散列,这样就不会出现任何模式。本文提出了一种采用sql预防、加密、加盐、散列等方法的新方法。SALT是使用两个参数动态生成的,其中一个是唯一的,并且SALT不存储在数据库中。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Three-Tier Password Security Algorithm for Online Databases
Password security is a significant issue for any authenticating process, and different researchers in the past have proposed techniques such as hashing, salting, honeywords to make the process most secured. We provide a self-guaranteed secure program and its access methods to mitigate the risk of illegal attacks like DDoS. This method ensures the security of a program by giving method level security that bolsters the further implemented security measures. A step-up approach is implementing the access security measures that protect against SQL injection and script attacks. Lucubration of various papers suggests that most systems are compromised at the storage of login credentials. Our solution ensures the security of such measures by obscurity. By using multiple layers of additional security procedures before storing the data decreases the risk of break-in exponentially. Our attempt to securely store passwords includes salting the passwords, encrypting them, and finally hashing them so that no patterns are visible. This paper presents a new method that involves SQLi prevention, encrypting, salting and then hashing the password. The SALT is generated dynamically using two parameters, one of which is unique, and the Salt is not stored in the database.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信