中文
相关论文

相关论文: Misbinding Raw Public Keys to Identities in TLS

200 篇论文

Risk-based Authentication (RBA) is an adaptive security measure that improves the security of password-based authentication by protecting against credential stuffing, password guessing, or phishing attacks. RBA monitors extra features…

密码学与安全 · 计算机科学 2020-09-15 Stephan Wiefling , Tanvi Patil , Markus Dürmuth , Luigi Lo Iacono

An ever-increasing number of critical infrastructures rely heavily on the assumption that security protocols satisfy a wealth of requirements. Hence, the importance of certifying e.g., privacy properties using methods that are better at…

密码学与安全 · 计算机科学 2026-03-17 Clément Aubert , Ross Horne , Christian Johansen , Sjouke Mauw

In this paper we're going to explore the ways in which security proofs can fail, and their broader lessons for security engineering. To mention just one example, Larry Paulson proved the security of SSL/TLS using his theorem prover Isabelle…

密码学与安全 · 计算机科学 2023-05-09 Ross Anderson , Nicholas Boucher

The current standard of Routing Protocol for Low Power and Lossy Networks (RPL) incorporates three modes of security: the Unsecured Mode (UM), Preinstalled Secure Mode (PSM), and the Authenticated Secure Mode (ASM). While the PSM and ASM…

网络与互联网体系结构 · 计算机科学 2020-11-30 Ahmed Raoof , Chung-Horng Lung , Ashraf Matrawy

In today's world, computer networks have become vulnerable to numerous attacks. In both wireless and wired networks, one of the most common attacks is man-in-the-middle attacks, within which session hijacking, context confusion attacks have…

密码学与安全 · 计算机科学 2022-02-02 Kailash Gogineni , Yongsheng Mei , Guru Venkataramani , Tian Lan

The Model Context Protocol (MCP) has emerged as a standard for connecting large language models (LLMs) with external tools. However, this MCP ecosystem introduces new security risks across hosts, servers, and registries. In this paper, we…

密码学与安全 · 计算机科学 2026-04-29 Xiaofan Li , Xing Gao

Leakage of confidential information represents a serious security risk. Despite a number of novel, theoretical advances, it has been unclear if and how quantitative approaches to measuring leakage of confidential information could be…

密码学与安全 · 计算机科学 2010-07-07 Jonathan Heusser , Pasquale Malacaria

With critical infrastructure increasingly relying on wireless communication, using end-to-end security such as TLS becomes imperative. However, TLS introduces significant overhead for resource-constrained devices and networks prevalent in…

密码学与安全 · 计算机科学 2024-11-05 Jörn Bodenhausen , Laurenz Grote , Michael Rademacher , Martin Henze

The Resource Public Key Infrastructure (RPKI) secures Internet routing by binding IP prefixes to authorized Autonomous Systems, yet its RSA foundations are vulnerable to quantum adversaries. A naive swap to post-quantum (PQ) signatures (eg…

网络与互联网体系结构 · 计算机科学 2026-03-10 Weitong Li , Yuze Li , Taejoong Chung

This paper describes a new password-based mutual authentication protocol for Web systems which prevents various kinds of phishing attacks. This protocol provides a protection of user's passwords against any phishers even if dictionary…

密码学与安全 · 计算机科学 2009-11-30 Yutaka Oiwa , Hajime Watanabe , Hiromitsu Takagi

Recently, Li et al. proposed a dynamic identity based authentication protocol for multi-server architecture. They claimed their protocol is secure and can withstand various attacks. But we found some security loopholes in the protocol.…

密码学与安全 · 计算机科学 2012-01-05 Weiwei Han

TR-069 is a standard for the remote management of end-user devices by service providers. Despite being implemented in nearly a billion devices, almost no research has been published on the security and privacy aspects of TR-069. The first…

网络与互联网体系结构 · 计算机科学 2020-01-09 Maximilian Hils , Rainer Böhme

Radio frequency (RF) fingerprinting, which extracts unique hardware imperfections of radio devices, has emerged as a promising physical-layer device identification mechanism in zero trust architectures and beyond 5G networks. In particular,…

密码学与安全 · 计算机科学 2026-05-28 Xinyu Cao , Bimal Adhikari , Shangqing Zhao , Jingxian Wu , Yanjun Pan

Computers and computer networks have become integral to virtually every aspect of modern life, with the Internet playing an indispensable role. Organizations, businesses, and individuals now store vast amounts of proprietary, confidential,…

密码学与安全 · 计算机科学 2025-07-28 Yuksel Arslan

Given the importance of privacy, many Internet protocols are nowadays designed with privacy in mind (e.g., using TLS for confidentiality). Foreseeing all privacy issues at the time of protocol design is, however, challenging and may become…

网络与互联网体系结构 · 计算机科学 2022-09-21 Olivier van der Toorn , Raffaele Sommese , Anna Sperotto , Roland van Rijswijk-Deij , Mattijs Jonker

The rapid development of information and network technologies motivates the emergence of various new computing paradigms, such as distributed computing, and edge computing. This also enables more and more network enterprises to provide…

密码学与安全 · 计算机科学 2021-02-01 Jinyong Chen , Reiner Dojen , Anca Jurcut

Trajectory data, which tracks movements through geographic locations, is crucial for improving real-world applications. However, collecting such sensitive data raises considerable privacy concerns. Local differential privacy (LDP) offers a…

密码学与安全 · 计算机科学 2025-03-11 I-Jung Hsu , Chih-Hsun Lin , Chia-Mu Yu , Sy-Yen Kuo , Chun-Ying Huang

Risk-based authentication (RBA) is an adaptive security measure to strengthen password-based authentication. RBA monitors additional implicit features during password entry such as device or geolocation information, and requests additional…

密码学与安全 · 计算机科学 2020-03-18 Stephan Wiefling , Luigi Lo Iacono , Markus Dürmuth

In this paper, we study the security requirements for remote authentication with password protected smart card. In recent years, several protocols for password-based authenticated key exchange have been proposed. These protocols are used…

密码学与安全 · 计算机科学 2012-07-24 Yongge Wang

Quantum key distribution (QKD) networks are expected to enable information-theoretical secure (ITS) communication over a large-scale network. Most researches on relay-based QKD network assume that all relays or nodes are completely…

量子物理 · 物理学 2024-02-02 Yi Luo , Qiong Li , Hao-Kun Mao