节点文献

开源智能终端认证漏洞挖掘及登录认证改进

Login authentication vulnerability mining and improved login authentication method based on an open source intelligent terminal

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 刘武王永科孙东红任萍刘柯

【Author】 LIU Wu;WANG Yongke;SUN Donghong;REN Ping;LIU Ke;Institute of Network Science and Network Space,Tsinghua University;Institute of Information Engineering,Chinese Academy of Sciences;College of Mathematics Science,Chongqing Normal University;China Citic Bank Branch of Tsinghua Science and Technology Park;

【机构】 清华大学网络科学与网络空间研究院中国科学院信息工程研究所重庆师范大学数学学院中信银行清华科技园支行

【摘要】 开源智能终端占智能终端市场的绝对优势,基于开源智能终端的应用层出不穷,但与此同时,其安全隐患也一样触目惊心。该文以典型社交网络APP登录认证为例,通过逆向分析当今市场上的主流Android应用,分析登录认证实现过程的机理,对登录认证机制进行安全性评估,挖掘基于现有认证机制的安全漏洞,并针对所发现的安全问题提出了登录认证机制改进方案,总结出一套安全实用的登录认证实践方案,有效提高移动智能终端系统的安全性。

【Abstract】 Open source intelligent terminals have many advantages in intelligent smart phones with endless applications of intelligent terminals based on open source codes.However,there are also many security risks for applications using intelligent terminals.This study analyzes the login authentication of a mainstream Android application in today’s market by reverse analysis.The security flaws for current login authentication mechanisms are evaluated to discover potential security vulnerabilities in intelligent terminal devices.An improved for login authentication scheme is then given which effectively improves the security of intelligent terminal systems.

【基金】 国家自然科学基金资助项目(61272427);国家科技支撑计划项目(2015AA016007,2015AA020101);贵州省科技支撑计划项目(20136020)
  • 【文献出处】 清华大学学报(自然科学版) ,Journal of Tsinghua University(Science and Technology) , 编辑部邮箱 ,2017年09期
  • 【分类号】TP393.08
  • 【被引频次】2
  • 【下载频次】163
节点文献中: 

本文链接的文献网络图示:

本文的引文网络