Search engine for discovering works of Art, research articles, and books related to Art and Culture
ShareThis
Javascript must be enabled to continue!

PAKE on the Web

View through CrossRef
Unlike existing password authentication mechanisms on the web that use passwords for client-side authentication only, password-authenticated key exchange (PAKE) protocols provide mutual authentication. In this article, we present an architecture to integrate existing PAKE protocols to the web. Our integration design consists of the client-side part and the server-side part. First, we implement the PAKE client-side functionality with a web browser plug-in, which provides a secure implementation base. The plug-in has a log-in window that can be customized by a user when the plug-in is installed. By checking the user-specific information in a log-in window, an ordinary user can easily detect a fake log-in window created by mobile code. The server-side integration comprises a web interface and a PAKE server. After a successful PAKE mutual authentication, the PAKE plug-in receives a one-time ticket and passes it to the web browser. The web browser authenticates itself by presenting this ticket over HTTPS to the web server. The plug-in then fades away and subsequent web browsing remains the same as usual, requiring no extra user education. Our integration design supports centralized log-ins for web applications from different web sites, making it appropriate for digital identity management. A prototype is developed to validate our design. Since PAKE protocols use passwords for mutual authentication, we believe that the deployment of this design will significantly mitigate the risk of phishing attacks.
Title: PAKE on the Web
Description:
Unlike existing password authentication mechanisms on the web that use passwords for client-side authentication only, password-authenticated key exchange (PAKE) protocols provide mutual authentication.
In this article, we present an architecture to integrate existing PAKE protocols to the web.
Our integration design consists of the client-side part and the server-side part.
First, we implement the PAKE client-side functionality with a web browser plug-in, which provides a secure implementation base.
The plug-in has a log-in window that can be customized by a user when the plug-in is installed.
By checking the user-specific information in a log-in window, an ordinary user can easily detect a fake log-in window created by mobile code.
The server-side integration comprises a web interface and a PAKE server.
After a successful PAKE mutual authentication, the PAKE plug-in receives a one-time ticket and passes it to the web browser.
The web browser authenticates itself by presenting this ticket over HTTPS to the web server.
The plug-in then fades away and subsequent web browsing remains the same as usual, requiring no extra user education.
Our integration design supports centralized log-ins for web applications from different web sites, making it appropriate for digital identity management.
A prototype is developed to validate our design.
Since PAKE protocols use passwords for mutual authentication, we believe that the deployment of this design will significantly mitigate the risk of phishing attacks.

Related Results

WEB PROGRAMMING
WEB PROGRAMMING
"Web Programming" is a comprehensive book that provides a detailed overview of various aspects of web programming. The book is co-authored by Dr. Chitra Ravi and Dr. Mohan Kumar S,...
Evaluación de accesibilidad web para limitaciones visuales utilizando agentes inteligentes
Evaluación de accesibilidad web para limitaciones visuales utilizando agentes inteligentes
La accesibilidad Web se basa en el concepto de que un producto o servicio Web pueda ser accedido y usado por el mayor número posible de personas, independientemente de las limitaci...
Editorial
Editorial
With the phenomenal growth of the Web, there is an everincreasing volume of data and information published in numerous Web pages. The research in Web mining aims to develop new tec...
Designing web-based learning opportunities for children related to health care (Preprint)
Designing web-based learning opportunities for children related to health care (Preprint)
BACKGROUND Hospitalisation is a significant and stressful experience for children and parents which may cause both short-term and long-term negative consequ...
Bioinformatics tool and web server development focusing on structural bioinformatics applications
Bioinformatics tool and web server development focusing on structural bioinformatics applications
This thesis is divided into two main sections: Part 1 describes the design, and evaluation of the accuracy of a new web server – PRotein Interactive MOdeling (PRIMO-Complexes) for ...
Implementasi Web Application Firewall untuk Melindungi Aplikasi Web dari Serangan Malware
Implementasi Web Application Firewall untuk Melindungi Aplikasi Web dari Serangan Malware
At this time Internet services have become a necessity no longer to provide information services, but have become important so there are many cases of websites being hacked by atta...
The Semantic Web
The Semantic Web
At the present time, the Web is primarily designed for human consumption and not for computer consumption. This may seem like an unusual state of affairs, given that the web is vas...
Design aspects of steel I-girders with corrugated steel webs
Design aspects of steel I-girders with corrugated steel webs
Corrugated web girders represent a new structural system emerged in the past two decades. The girder’s flanges provide the flexural strength of the girder with no contribution from...

Back to Top