返回
SSL/TLS session-aware user authentication revisited
DOI:10.1016/j.cose.2008.04.005.png)
摘要
En 中文
Man-in-the-middle (MITM) attacks pose a serious threat to SSL/TLS-based e-commerce applications. in Oppliger R, Hauser R, Basin D [SSL/TLS session-aware user authentication or how to effectively thwart the man-in-the-middle. Computer Communications August 2006;29(12):2238-46] and Oppliger R, Hauser R, Basin D [SSL/TLS session-aware user authentication. IEEE Computer March 2008;41(3) 59-65], we introduced the notion of SSL/TLS session-aware user authentication to protect SSL/TLS-based e-commerce applications against MITM attacks and we proposed an implementation based on impersonal authentication tokens. In this paper, we present a number of extensions of the basic idea. These include multi -institution tokens, possibilities for changing the PIN, and different ways of making several popular and widely deployed user authentication systems SSL/TLS session-aware. (C) 2008 Elsevier Ltd. All rights reserved.
Keyword:
electronic commerce
security
phishing
man-in-the-middle attack
SSL/TLS protocol
SSL/TLS session-aware
user authentication
AI总结
对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。
期刊
C
IF:
5.4
论文数:
4.6K
被引数:
1.4W
机构
引用论文
没有更多内容

