Journal on Communications ›› 2019, Vol. 40 ›› Issue (2): 174-187.doi: 10.11959/j.issn.1000-436x.2019044

• Correspondences • Previous Articles     Next Articles

Single password authentication method for remote user based on mobile terminal assistance

Yuan XU1,Chao YANG2,Li YANG3   

  1. 1 Experimental Teaching Management Training Center,Xi’an University of Finance and Economics,Xi’an 710100,China
    2 Information Network Technology Center,Xidian University,Xi’an 710071,China
    3 School of Cyber Engineering,Xidian University,Xi’an 710071,China
  • Revised:2018-09-23 Online:2019-02-01 Published:2019-03-04
  • Supported by:
    The National Basic Research Program of China(2017YFGX110123);The Science and Technology Innovation Planning Project of Shaanxi Province(201809168CX9JC10);The National Natural Science Foundation of China(61672415);The Research Program of Education and Teaching Reform of Xi’an University of Finance and Economics in 2018(18xcj36)

Abstract:

To address the issue that users frequently reuse their weak passwords in password-based authentication system,single password authentication based on secret sharing between server and mobile terminal (SPASS) was proposed,which allows a remote user to use a single password to authenticate to multiple services securely and has no need to store any secret of the user in the client PC.Even when the mobile device is lost or stolen,no damage to the user’s information will be induced.Security analysis and performance test show that SPASS greatly improves the security of the user’s secret information and resists dictionary attacks,honeypot attacks,cross-site scripting attacks etc.Furthermore,the proposed scheme can lighten burden of the user’s memory,reduce the storage pressure and easy to be deployed.

Key words: password-based authentication, secret sharing, authentication based on mobile terminal, malware, dictionary attack

CLC Number: 

No Suggested Reading articles found!