Logo image
A Machine-Based Authentication Mechanism to Prevent from Identity Theft
Thesis

A Machine-Based Authentication Mechanism to Prevent from Identity Theft

Jia-Huei Chen
Masters, 國立清華大學, 資訊系統與應用研究所
2004

Abstract

身份竊取 機器認證 使用者認證 identity theft machine-based authentication user authentication
Password authentication is regard as one of the simplest and most convenient authentication mechanisms. This authentication mechanism is usually employed with SSL protocol in the current web-based application systems. However, password-based authentication mechanisms are unable to resist the problem of identity theft. The intruders can take dictionary attacks on them and then impersonating legal users to access resources which only members have. To prevent from identity theft, client authentication is a solution. The digital certificate is a typical client authentication mechanism in the SSL protocol. Although SSL does offer it, the security service is optional and usually omitted. This is because of the fact that users typically do not have the necessary asymmetric key pair. Later, several client authentication mechanisms, such as one-time password tokens, smart cards and smart USB tokens, mobile phones and biometrics, are proposed to solve the problem of identity theft. Tow-factor authentication mechanism combines one of the above mechanisms and password authentication. Unfortunately, there are some flaws in these client authentication mechanisms by our analysis. Therefore, we improve the idea of “Product Activation” addressed by Microsoft Co. to build a authentication mechanism. This mechanism provides the user’s identity by using hardware and software components in a machine. There are three features in our mechanism: (1) The main authentication data, also called HS-Code, is constructed of 10 components. (2) The use of weight filed is our idea for fault-tolerance. It can reduce the times of re-authentication for users. (3) Using a suit technology including duplication machine, restrict functions, and flexible threshold and weight to make users interact with the system everywhere and every computers. Furthermore, we evaluate this mechanism we proposed is superior to others by five criteria. To establish this mechanism, we utilize the WMI which is the API in the platform of Microsoft Windows to implement the core technology. And our system is similar with current web-based application system, so any organization can deploy this mechanism quickly and can afford the implementation cost.

Metrics

1 Record Views

Details

Logo image