The majority of systems rely on user authentication on passwords, but passwords have so many weaknesses and widespread use that easily raise significant security concerns, regardless of their encrypted form. Users hold the same password for different accounts, administrators never check password files for flaws that might lead to a successful cracking, and the lack of a tight security policy regarding regular password replacement are a few problems that need to be addressed. The proposed research work aims at enhancing this security mechanism, prevent penetrations, password theft, and attempted break-ins towards securing computing systems. The selected solution approach is two-folded; it implements a two-factor authentication scheme to prevent unauthorized access, accompanied by Honeyword principles to detect corrupted or stolen tokens. Both can be integrated into any platform or web application with the use of QR codes and a mobile phone.
翻译:大多数系统依靠密码上的用户认证,但密码有许多弱点和广泛使用,很容易引起严重的安全关切,不管其加密形式如何。用户持有不同的密码,管理员从不检查密码文件可能导致成功破解的缺陷,缺乏关于定期更换密码的严格安全政策是需要解决的几个问题。提议的研究工作旨在加强这一安全机制,防止渗透、密码盗窃和试图破门而入,以保障计算机系统的安全。选定的解决办法有两重;它实施双要素认证计划,防止未经授权的进入,并辅以蜂蜜字原则,以发现腐败或被盗的标志。两者都可以纳入任何平台或网络应用程序,同时使用QR码和移动电话。