基于实名认证的名人身份证号码隐私泄露研究

IF 1.5 Q3 COMPUTER SCIENCE, INFORMATION SYSTEMS
H. Yue, Zebin Song, Mengli Zhao, Lijia Yang
{"title":"基于实名认证的名人身份证号码隐私泄露研究","authors":"H. Yue, Zebin Song, Mengli Zhao, Lijia Yang","doi":"10.1002/spy2.442","DOIUrl":null,"url":null,"abstract":"The Internet real‐name system is widely implemented among Chinese Internet users, and many commonly used apps in China exist the functions of real‐name authentication. However, our study found that many apps do not have effective restrictions on user's operations of real‐name authentication, resulting in users being able to frequently perform unsuccessful real‐name authentication attempts. This vulnerability can help an attacker crack celebrity's ID card number by enumeration attacks, and a feasible cracking method was proposed in this paper. First, the information of birth date, birth place, and life experiences of a celebrity is collected from the platforms that display celebrities' personal information (e.g., Wikipedia, Baidu Baike, etc.). In this process, an information extraction method is used to infer permanent residences from life experiences. Then, the possible ID card numbers of a celebrity can be constructed by using the information of birth date, birth place, and permanent residences. Finally, these possible ID card numbers will be verified by sending requests to platforms that have vulnerabilities in the function of user real‐name authentication, until the real ID card number of a celebrity being cracked. This paper conducted cracking experiments on two groups of celebrities. The first group of celebrities is collected from the news events of privacy leakage that were publicly available online, and the second group of celebrities is randomly selected from two encyclopedia platforms. The experimental results showed that the success rate of cracking the ID card numbers of celebrities is 53.9%, which verified the effectiveness of the proposed cracking method. Besides, this paper proposed some security precaution suggestions to solve this security problem, and the implementation, feasibility, potential impact, expected effectiveness of these measures were also analyzed. To our knowledge, our paper is the first to point out the issue of privacy leakage of celebrity's ID card number caused by apps' real‐name authentication functions in China. We believe that our research will attract widespread attention from society regarding celebrity's privacy information protection.","PeriodicalId":29939,"journal":{"name":"Security and Privacy","volume":null,"pages":null},"PeriodicalIF":1.5000,"publicationDate":"2024-07-11","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"Research on privacy leakage of celebrity's ID card number based on real‐name authentication\",\"authors\":\"H. Yue, Zebin Song, Mengli Zhao, Lijia Yang\",\"doi\":\"10.1002/spy2.442\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"The Internet real‐name system is widely implemented among Chinese Internet users, and many commonly used apps in China exist the functions of real‐name authentication. However, our study found that many apps do not have effective restrictions on user's operations of real‐name authentication, resulting in users being able to frequently perform unsuccessful real‐name authentication attempts. This vulnerability can help an attacker crack celebrity's ID card number by enumeration attacks, and a feasible cracking method was proposed in this paper. First, the information of birth date, birth place, and life experiences of a celebrity is collected from the platforms that display celebrities' personal information (e.g., Wikipedia, Baidu Baike, etc.). In this process, an information extraction method is used to infer permanent residences from life experiences. Then, the possible ID card numbers of a celebrity can be constructed by using the information of birth date, birth place, and permanent residences. Finally, these possible ID card numbers will be verified by sending requests to platforms that have vulnerabilities in the function of user real‐name authentication, until the real ID card number of a celebrity being cracked. This paper conducted cracking experiments on two groups of celebrities. The first group of celebrities is collected from the news events of privacy leakage that were publicly available online, and the second group of celebrities is randomly selected from two encyclopedia platforms. The experimental results showed that the success rate of cracking the ID card numbers of celebrities is 53.9%, which verified the effectiveness of the proposed cracking method. Besides, this paper proposed some security precaution suggestions to solve this security problem, and the implementation, feasibility, potential impact, expected effectiveness of these measures were also analyzed. To our knowledge, our paper is the first to point out the issue of privacy leakage of celebrity's ID card number caused by apps' real‐name authentication functions in China. We believe that our research will attract widespread attention from society regarding celebrity's privacy information protection.\",\"PeriodicalId\":29939,\"journal\":{\"name\":\"Security and Privacy\",\"volume\":null,\"pages\":null},\"PeriodicalIF\":1.5000,\"publicationDate\":\"2024-07-11\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Security and Privacy\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1002/spy2.442\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"Q3\",\"JCRName\":\"COMPUTER SCIENCE, INFORMATION SYSTEMS\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Security and Privacy","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1002/spy2.442","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q3","JCRName":"COMPUTER SCIENCE, INFORMATION SYSTEMS","Score":null,"Total":0}
引用次数: 0

摘要

网络实名制在中国网民中广泛推行,国内许多常用的应用程序都存在实名认证功能。然而,我们在研究中发现,很多应用程序并没有对用户的实名认证操作进行有效限制,导致用户可以频繁地进行不成功的实名认证尝试。这一漏洞可以帮助攻击者通过枚举攻击破解名人的身份证号码,本文提出了一种可行的破解方法。首先,从展示名人个人信息的平台(如维基百科、百度百科等)收集名人的出生日期、出生地和生活经历等信息。在此过程中,使用信息提取方法从生活经历中推断出永久居住地。然后,根据出生日期、出生地和常住地等信息构建名人可能的身份证号码。最后,通过向用户实名认证功能存在漏洞的平台发送请求,对这些可能的身份证号码进行验证,直至破解出名人的真实身份证号码。本文对两组名人进行了破解实验。第一组名人是从网上公开的隐私泄露新闻事件中收集的,第二组名人是从两个百科平台中随机抽取的。实验结果表明,破解名人身份证号码的成功率为 53.9%,验证了所提破解方法的有效性。此外,本文还针对这一安全问题提出了一些安全防范建议,并对这些措施的实施、可行性、潜在影响、预期效果等进行了分析。据我们所知,我们的论文在国内首次指出了应用程序实名认证功能导致的名人身份证号码隐私泄露问题。相信我们的研究会引起社会对名人隐私信息保护的广泛关注。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Research on privacy leakage of celebrity's ID card number based on real‐name authentication
The Internet real‐name system is widely implemented among Chinese Internet users, and many commonly used apps in China exist the functions of real‐name authentication. However, our study found that many apps do not have effective restrictions on user's operations of real‐name authentication, resulting in users being able to frequently perform unsuccessful real‐name authentication attempts. This vulnerability can help an attacker crack celebrity's ID card number by enumeration attacks, and a feasible cracking method was proposed in this paper. First, the information of birth date, birth place, and life experiences of a celebrity is collected from the platforms that display celebrities' personal information (e.g., Wikipedia, Baidu Baike, etc.). In this process, an information extraction method is used to infer permanent residences from life experiences. Then, the possible ID card numbers of a celebrity can be constructed by using the information of birth date, birth place, and permanent residences. Finally, these possible ID card numbers will be verified by sending requests to platforms that have vulnerabilities in the function of user real‐name authentication, until the real ID card number of a celebrity being cracked. This paper conducted cracking experiments on two groups of celebrities. The first group of celebrities is collected from the news events of privacy leakage that were publicly available online, and the second group of celebrities is randomly selected from two encyclopedia platforms. The experimental results showed that the success rate of cracking the ID card numbers of celebrities is 53.9%, which verified the effectiveness of the proposed cracking method. Besides, this paper proposed some security precaution suggestions to solve this security problem, and the implementation, feasibility, potential impact, expected effectiveness of these measures were also analyzed. To our knowledge, our paper is the first to point out the issue of privacy leakage of celebrity's ID card number caused by apps' real‐name authentication functions in China. We believe that our research will attract widespread attention from society regarding celebrity's privacy information protection.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
5.30%
发文量
80
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信