Authentication in Insecure Environments: Using Visual Cryptography and Non-Transferable Credentials in Practise
暫譯: 不安全環境中的身份驗證:實踐視覺密碼學與不可轉讓憑證
Sebastian Pape
相關主題
商品描述
Sebastian Pape discusses two different scenarios for authentication. On the one hand, users cannot trust their devices and nevertheless want to be able to do secure authentication. On the other hand, users may not want to be tracked while their service provider does not want them to share their credentials. Many users may not be able to determine whether their device is trustworthy, i.e. it might contain malware. One solution is to use visual cryptography for authentication. The author generalizes this concept to human decipherable encryption schemes and establishes a relationship to CAPTCHAS. He proposes a new security model and presents the first visual encryption scheme which makes use of noise to complicate the adversary's task. To prevent service providers from keeping their users under surveillance, anonymous credentials may be used. However, sometimes it is desirable to prevent the users from sharing their credentials. The author compares existing approaches based on non-transferable anonymous credentials and proposes an approach which combines biometrics and smartcards.
商品描述(中文翻譯)
Sebastian Pape 討論了兩種不同的身份驗證情境。一方面,使用者無法信任他們的設備,但仍然希望能夠進行安全的身份驗證。另一方面,使用者可能不希望被追蹤,而服務提供者則不希望他們分享自己的憑證。許多使用者可能無法判斷他們的設備是否可信,即設備可能包含惡意軟體。一種解決方案是使用視覺密碼學進行身份驗證。作者將這一概念推廣到人類可解讀的加密方案,並建立與 CAPTCHA 的關係。他提出了一種新的安全模型,並展示了第一個利用噪音來複雜化對手任務的視覺加密方案。為了防止服務提供者對其使用者進行監控,可以使用匿名憑證。然而,有時候希望防止使用者分享他們的憑證。作者比較了基於不可轉讓的匿名憑證的現有方法,並提出了一種結合生物識別技術和智慧卡的方案。