The Experts below are selected from a list of 27 Experts worldwide ranked by ideXlab platform

Taekyoung Kwon - One of the best experts on this subject based on the ideXlab platform.

  • Refinement and improvement of virtual Software Token protocols
    IEEE Communications Letters, 2004
    Co-Authors: Taekyoung Kwon
    Abstract:

    Recently, the Virtual Software Token Protocol (VSTP) was proposed as a practical method for secure public key infrastructure (PKI) roaming. It enabled users not to keep their private keys in portable storage. Instead, a set of servers was deployed for the purpose. However, a weakness has been found from the original assumption. The split password was vulnerable to the so-called split on-line attack. So, this letter refines the original scheme with a new restriction and proposes its improved version as well.

Jie Wang - One of the best experts on this subject based on the ideXlab platform.

  • A More Efficient Improvement of the Virtual Software Token Protocols
    IEICE Transactions on Communications, 2006
    Co-Authors: Shuhong Wang, Feng Bao, Jie Wang
    Abstract:

    The Virtual Software Token Protocol was proposed by Know as a practical method for secure public key infrastructure roaming. However, he recently found a weakness of the protocol under the original assumption, and proposed two revised versions, namely refinement and improvement, which lost the desirable properties of scalability and efficiency respectively. In this letter, a secure improvement is proposed for better performance in both scalability and efficiency. Unlike the author's improvement, our improvement provides parallel execution as the original protocol did.

Jeanmarc Seigneur - One of the best experts on this subject based on the ideXlab platform.

  • context aware multifactor authentication survey
    Computer and Information Security Handbook (Third Edition), 2017
    Co-Authors: Emin Huseynov, Jeanmarc Seigneur
    Abstract:

    Abstract Multifactor authentication is one of the de facto standards for systems requiring strong security. In most cases, multifactor authentication is complex and not user-friendly because it requires additional steps as far as end users are concerned. With two-factor authentication, in addition to entering a username and a password (first factor), users need to enter an additional code (second factor) manually that they receive by short message service or look up in a previously printed list of passwords, or that is generated by a hardware or Software Token. So, although introducing additional authentication factors greatly increases the level of security, it could also become frustrating for end users. This chapter reviews a wide variety of modern and classic multifactor authentication systems and methods.

Shuhong Wang - One of the best experts on this subject based on the ideXlab platform.

  • A More Efficient Improvement of the Virtual Software Token Protocols
    IEICE Transactions on Communications, 2006
    Co-Authors: Shuhong Wang, Feng Bao, Jie Wang
    Abstract:

    The Virtual Software Token Protocol was proposed by Know as a practical method for secure public key infrastructure roaming. However, he recently found a weakness of the protocol under the original assumption, and proposed two revised versions, namely refinement and improvement, which lost the desirable properties of scalability and efficiency respectively. In this letter, a secure improvement is proposed for better performance in both scalability and efficiency. Unlike the author's improvement, our improvement provides parallel execution as the original protocol did.

Huseynov Emin - One of the best experts on this subject based on the ideXlab platform.

  • Context-aware multifactor authentication for the augmented human
    'American Society for Clinical Pathology (ASCP)', 2020
    Co-Authors: Huseynov Emin
    Abstract:

    Multi-factor authentication is currently one of the de-facto standards for systems requiring strong security. In most of the cases, multi-factor authentication is rather complex and not very user-friendly, as it requires additional steps as far as end-users are concerned: e.g. with two-factor authentication, in addition to entering a username and a password (usually considered as a first factor), users need to manually enter an additional code (second factor) that they either receive by text messages, look up in a previously printed list of passwords or generated by a hardware or Software Token. An extensive review of potential security risks that multi-factor authentication is capable of mitigating is a significant part of this thesis. The thesis will review phishing as one of the biggest end-user targeted attacks and describe the security risks as well as modern methods of such attacks that can potentially lead to theft of sensitive data, such as user credentials, passwords and/or credit card information. The main purpose of this research is to review existing multi-factor authentication systems, primarily in corporate applications, and overcome existing gaps and shortcomings with introducing contexts of various types of additional authentication factors. Context as a word means the influence factors and events related to a particular situation. In our case, the meaning remains the same, it is only worth mentioning that in the situation we are applying the context - it is namely the user authentication operation or sequence of operations