Decentralized Identity and Password Authentication System based on Block Chain

Zhao Yun, Cui Chao, Wang Haoling, Liu Tao, Jiang Hefang
{"title":"Decentralized Identity and Password Authentication System based on Block Chain","authors":"Zhao Yun, Cui Chao, Wang Haoling, Liu Tao, Jiang Hefang","doi":"10.1109/ICPICS55264.2022.9873634","DOIUrl":null,"url":null,"abstract":"The most widely used user authentication method on the Internet is abstract password authentication, That is to say, the user and his name - password to each server established, and then use it to authenticate. Although they are widely used because of their simple operation and high experience, the security of authentication provided by them is not high, and the server operator is positioned as a trusted party who can fully control the user’s identity. To solve this problem, many identity recognition systems adopt the concepts of public key encryption and decentralization,but the requirement that users generate and manage public and private key pairs, and that users often do not have such expertise, has become a key factor in the failure of PKI for many end users. To sum up, this paper proposes a decentralized identity and password authentication system (DIA) based on block chain as an identity and authentication framework. Users can register their own user name password pairs and use them as general credentials. The system provides a global name space, meaningful user names, and the ability to resist user name conflict attacks. User’s identity to any server can be applied to authenticate a user, to the server without having to disclose any information relating to the password,, so it is impossible to carry out offline dictionary attack on the password.","PeriodicalId":257180,"journal":{"name":"2022 IEEE 4th International Conference on Power, Intelligent Computing and Systems (ICPICS)","volume":"12 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2022-07-29","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2022 IEEE 4th International Conference on Power, Intelligent Computing and Systems (ICPICS)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICPICS55264.2022.9873634","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

The most widely used user authentication method on the Internet is abstract password authentication, That is to say, the user and his name - password to each server established, and then use it to authenticate. Although they are widely used because of their simple operation and high experience, the security of authentication provided by them is not high, and the server operator is positioned as a trusted party who can fully control the user’s identity. To solve this problem, many identity recognition systems adopt the concepts of public key encryption and decentralization,but the requirement that users generate and manage public and private key pairs, and that users often do not have such expertise, has become a key factor in the failure of PKI for many end users. To sum up, this paper proposes a decentralized identity and password authentication system (DIA) based on block chain as an identity and authentication framework. Users can register their own user name password pairs and use them as general credentials. The system provides a global name space, meaningful user names, and the ability to resist user name conflict attacks. User’s identity to any server can be applied to authenticate a user, to the server without having to disclose any information relating to the password,, so it is impossible to carry out offline dictionary attack on the password.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
基于区块链的去中心化身份与密码认证系统
Internet上应用最广泛的用户认证方法是抽象密码认证,也就是说,将用户和他的姓名-密码建立到每个服务器上,然后用它来进行认证。虽然由于其操作简单、经验高而被广泛使用,但其提供的认证安全性并不高,服务器运营商被定位为可以完全控制用户身份的可信方。为了解决这个问题,许多身份识别系统采用了公钥加密和去中心化的概念,但是用户需要生成和管理公钥和私钥对,而用户往往不具备这样的专业知识,这已经成为许多最终用户PKI失败的关键因素。综上所述,本文提出了一种基于区块链的去中心化身份与密码认证系统(DIA)作为身份与认证框架。用户可以注册自己的用户名密码对,并将其用作通用凭据。系统提供了全局的名称空间、有意义的用户名以及抵抗用户名冲突攻击的能力。用户的身份对任何服务器都可以应用于对用户进行身份验证,对服务器不需要透露任何与密码有关的信息,因此不可能对密码进行离线字典攻击。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Research on small object detection methods based on deep learning Insulation State Assessment of Cable Intermediate Joint based on Fuzzy Comprehensive Evaluation with Variable Weight Development of Automatic Testing Device for Electric Iron Accessories Measures to Solve the High Abnormal Rate of Disconnector Test Values Fault Pattern Recognition Method for DC-DC Power by Using Output Voltage Waveform Analysis
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1