CICI: Secure Data Architecture: Improving the Security and Usability of Two-Factor Authentication for Cyberinfrastructure
CICI:安全数据架构:提高网络基础设施双因素身份验证的安全性和可用性
基本信息
- 批准号:1547350
- 负责人:
- 金额:$ 24.97万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Standard Grant
- 财政年份:2016
- 资助国家:美国
- 起止时间:2016-01-01 至 2021-06-30
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
Password authentication is a critical vulnerability in cyberinfrastructure because typical passwords are memorable and easily guessed, leaving them vulnerable to malicious actors. One well-recognized method for strengthening the password security is Two-Factor Authentication (TFA), in which the password is complemented by an additional authentication factor such as a mobile phone or a dedicated token (e.g., a USB dongle). However, current TFA mechanisms do not offer sufficient security and usability. This project breaks new ground towards improving both of these aspects. It designs, implements and evaluates TFA schemes that not only protect against on-line guessing attacks, but also against off-line dictionary attacks in case of server or mobile device compromise. Moreover, the project aims to do so without degrading usability compared to password-only authentication. The creation of formal security models for TFA schemes allow for better understanding of TFA security in general. The resulting research prototypes will be of immense value in future research on building resilient and usable authentication services. The project integrates research into educational activities in the form of advanced curriculum development as well as high school and K-12 student mentoring in the area of Identity and Access Management.The design of new TFA protocols offers security against on-line guessing and offline dictionary attacks. The project formally proves the security of these protocols in a strong security model for TFA protocols that is being introduced as an extension to well-established password-authenticated key exchange (PAKE) models. The goal is to design the TFA protocols in a modular way, allowing for the use of independent device and server components, and enabling the use of the developed schemes with existing password protocols and without the need to modify the server software. Moreover, the research involves developing and testing TFA systems which will instantiate the proposed protocols. The goal is a TFA systems design that utilizes automated and user-transparent data channel between the mobile device and the client, falling back to localized wireless radio communication only when such a channel is unavailable. Such construction would provide high usability since the user experience of the login process would be almost equivalent to password-only authentication. Finally, the project involves conducting rigorous usability studies in the lab environment and field settings to evaluate the performance, usability, and adoption potential of the proposed approaches.
密码身份验证是网络基础结构中的一个关键漏洞,因为典型的密码令人难忘,并且容易猜测,因此它们容易受到恶意演员的影响。增强密码安全性的一种良好认可的方法是两因素身份验证(TFA),其中密码以其他身份验证因子(例如手机或专用令牌)(例如USB Dongle)进行补充。但是,当前的TFA机制无法提供足够的安全性和可用性。该项目打破了改善这两个方面的新基础。它设计,实施和评估不仅可以防止在线猜测攻击的TFA方案,还可以在服务器或移动设备妥协的情况下进行离线词典攻击。此外,与仅密码身份验证相比,该项目旨在这样做而不会降低可用性。为TFA方案创建形式的安全模型,可以更好地了解TFA安全性。在建立弹性和可用身份验证服务的未来研究中,由此产生的研究原型将具有巨大的价值。该项目以高级课程开发以及高中和K-12学生指导的形式将研究整合到身份和访问管理领域。新的TFA协议的设计为在线猜测和离线词典攻击提供了安全性。该项目正式在TFA协议的强安全模型中正式证明了这些协议的安全性,该协议正在引入,该模型是针对良好的密码实体构造的密钥交换(PAKE)模型的扩展。目标是以模块化的方式设计TFA协议,允许使用独立的设备和服务器组件,并启用具有现有密码协议的开发方案的使用,而无需修改服务器软件。此外,该研究涉及开发和测试TFA系统,这些系统将实例化提议的协议。 目标是一种TFA系统设计,该设计利用移动设备和客户端之间的自动化和用户透明的数据通道,仅在无法使用该通道时落入局部无线无线电通信。由于登录过程的用户体验几乎等同于仅密码的身份验证,因此这种构造将提供高可用性。最后,该项目涉及在实验室环境和现场设置中进行严格的可用性研究,以评估拟议方法的性能,可用性和采用潜力。
项目成果
期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
数据更新时间:{{ journalArticles.updateTime }}
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Nitesh Saxena其他文献
Gene Regulation and Species-Specific Evolution of Free Flight Odor Tracking in Drosophila
果蝇自由飞行气味追踪的基因调控和物种特异性进化
- DOI:
10.1093/molbev/msx241 - 发表时间:
2018 - 期刊:
- 影响因子:10.7
- 作者:
B. Houot;Laurie Cazalé;S. Fraichard;C. Everaerts;Nitesh Saxena;S. Sane;J. Ferveur - 通讯作者:
J. Ferveur
PASSAT: Single Password Authenticated Secret-Shared Intrusion-Tolerant Storage with Server Transparency
PASSAT:具有服务器透明性的单密码验证秘密共享入侵容忍存储
- DOI:
- 发表时间:
2021 - 期刊:
- 影响因子:0
- 作者:
Kiavash Satvat;Maliheh Shirvanian;Nitesh Saxena - 通讯作者:
Nitesh Saxena
Robust self-keying mobile ad hoc networks
强大的自键控移动自组织网络
- DOI:
10.1016/j.comnet.2006.07.009 - 发表时间:
2007 - 期刊:
- 影响因子:0
- 作者:
C. Castelluccia;Nitesh Saxena;J. Yi - 通讯作者:
J. Yi
Towards Sensing-Enabled RFID Security and Privacy
迈向传感型 RFID 安全和隐私
- DOI:
10.4018/978-1-4666-1990-6.ch003 - 发表时间:
2013 - 期刊:
- 影响因子:0
- 作者:
Di Ma;Nitesh Saxena - 通讯作者:
Nitesh Saxena
Secure Device Pairing Based on a Visual Channel: Design and Usability Study
基于视觉通道的安全设备配对:设计和可用性研究
- DOI:
10.1109/tifs.2010.2096217 - 发表时间:
2011 - 期刊:
- 影响因子:6.8
- 作者:
Nitesh Saxena;Jan;Kari Kostiainen;N. Asokan - 通讯作者:
N. Asokan
Nitesh Saxena的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Nitesh Saxena', 18)}}的其他基金
Collaborative Research: SaTC: CORE: Medium: Bubble Aid: Assistive AI to Improve the Robustness and Security of Reading Hand-Marked Ballots
合作研究:SaTC:核心:媒介:Bubble Aid:辅助人工智能提高阅读手写选票的稳健性和安全性
- 批准号:
2154507 - 财政年份:2022
- 资助金额:
$ 24.97万 - 项目类别:
Continuing Grant
CICI: UCSS: Towards Secure and Usable Push Notification Authentication for Collaborative Scientific Infrastructures
CICI:UCSS:为协作科学基础设施实现安全可用的推送通知身份验证
- 批准号:
2115107 - 财政年份:2021
- 资助金额:
$ 24.97万 - 项目类别:
Standard Grant
CICI: UCSS: Towards Secure and Usable Push Notification Authentication for Collaborative Scientific Infrastructures
CICI:UCSS:为协作科学基础设施实现安全可用的推送通知身份验证
- 批准号:
2139358 - 财政年份:2021
- 资助金额:
$ 24.97万 - 项目类别:
Standard Grant
Collaborative Research: SaTC: TTP: Medium: Intrusion-Tolerant Outsourced Storage for Cyber-Infrastructure
协作研究:SaTC:TTP:中:网络基础设施的耐入侵外包存储
- 批准号:
2201465 - 财政年份:2021
- 资助金额:
$ 24.97万 - 项目类别:
Standard Grant
SaTC: TTP: Small: SPHINX: A Password Store that Perfectly Hides Passwords from Itself
SaTC:TTP:小型:SPHINX:完美隐藏密码的密码存储
- 批准号:
2152669 - 财政年份:2021
- 资助金额:
$ 24.97万 - 项目类别:
Standard Grant
Collaborative Research: SaTC: TTP: Medium: Intrusion-Tolerant Outsourced Storage for Cyber-Infrastructure
协作研究:SaTC:TTP:中:网络基础设施的耐入侵外包存储
- 批准号:
2030501 - 财政年份:2020
- 资助金额:
$ 24.97万 - 项目类别:
Standard Grant
SaTC: TTP: Small: SPHINX: A Password Store that Perfectly Hides Passwords from Itself
SaTC:TTP:小型:SPHINX:完美隐藏密码的密码存储
- 批准号:
1714807 - 财政年份:2017
- 资助金额:
$ 24.97万 - 项目类别:
Standard Grant
TWC: Small: Collaborative: Spoof-Resistant Smartphone Authentication using Cooperating Wearables
TWC:小型:协作:使用协作可穿戴设备进行防欺骗智能手机身份验证
- 批准号:
1526524 - 财政年份:2015
- 资助金额:
$ 24.97万 - 项目类别:
Standard Grant
EAGER: Establishing Secure Wireless Connections via Playful User Engagement
EAGER:通过有趣的用户参与建立安全的无线连接
- 批准号:
1255919 - 财政年份:2012
- 资助金额:
$ 24.97万 - 项目类别:
Standard Grant
CT-ISG: User-Aided Secure Association of Wireless Devices
CT-ISG:用户辅助的无线设备安全关联
- 批准号:
1228236 - 财政年份:2012
- 资助金额:
$ 24.97万 - 项目类别:
Standard Grant
相似国自然基金
面向边缘智能的车联网数据安全关键技术研究
- 批准号:62372100
- 批准年份:2023
- 资助金额:50 万元
- 项目类别:面上项目
基于联邦学习和区块链的物联网安全可信数据共享理论与技术研究
- 批准号:62366004
- 批准年份:2023
- 资助金额:32 万元
- 项目类别:地区科学基金项目
基于多维数据特征的异构内存系统高效安全保障方法研究
- 批准号:62302182
- 批准年份:2023
- 资助金额:30 万元
- 项目类别:青年科学基金项目
数据智能赋能的城市安全风险评估、应急响应机制与决策支持研究
- 批准号:72334003
- 批准年份:2023
- 资助金额:165 万元
- 项目类别:重点项目
基于文件操作特征分析的智能移动终端数据安全研究
- 批准号:62372465
- 批准年份:2023
- 资助金额:50.00 万元
- 项目类别:面上项目
相似海外基金
CICI: UCSS: Maximizing Data Utility and Participant Privacy through Usable, Secure Data Workflows for Human-Centered AI Research
CICI:UCSS:通过可用、安全的数据工作流程实现以人为本的人工智能研究,最大限度地提高数据效用和参与者隐私
- 批准号:
2232690 - 财政年份:2023
- 资助金额:
$ 24.97万 - 项目类别:
Standard Grant
CICI: UCSS: Enhancing Integrity and Confidentiality for Secure Distributed Data Sharing
CICI:UCSS:增强安全分布式数据共享的完整性和保密性
- 批准号:
2114202 - 财政年份:2021
- 资助金额:
$ 24.97万 - 项目类别:
Standard Grant
CICI: RDP: Open Badge Researcher Credentials for Secure Access to Restricted and Sensitive Data
CICI:RDP:用于安全访问受限和敏感数据的开放徽章研究人员证书
- 批准号:
1839868 - 财政年份:2018
- 资助金额:
$ 24.97万 - 项目类别:
Standard Grant
CICI: SSC: Development of a Secure and Privacy-Preserving Workflow Architecture for Dynamic Data Sharing in Scientific Infrastructures
CICI:SSC:开发安全且保护隐私的工作流程架构,用于科学基础设施中的动态数据共享
- 批准号:
1839746 - 财政年份:2018
- 资助金额:
$ 24.97万 - 项目类别:
Standard Grant
CICI: Secure and Resilient Architecture: Campus Infrastructure for Microscale, Privacy-Conscious, Data-Driven Planning
CICI:安全和弹性架构:用于微型、隐私意识、数据驱动规划的园区基础设施
- 批准号:
1642120 - 财政年份:2017
- 资助金额:
$ 24.97万 - 项目类别:
Standard Grant