发明授权
- 专利标题: Method and apparatus for secure online transactions
- 专利标题(中): 用于安全在线交易的方法和装置
-
申请号: US11998890申请日: 2007-12-03
-
公开(公告)号: US08352738B2公开(公告)日: 2013-01-08
- 发明人: Bryan Parno , Cynthia Kuo , Adrian Perrig
- 申请人: Bryan Parno , Cynthia Kuo , Adrian Perrig
- 申请人地址: US PA Pittsburgh
- 专利权人: Carnegie Mellon University
- 当前专利权人: Carnegie Mellon University
- 当前专利权人地址: US PA Pittsburgh
- 代理机构: Jones Day
- 主分类号: H04L9/32
- IPC分类号: H04L9/32 ; G06Q20/00
摘要:
Phishing attacks succeed by exploiting a user's inability to distinguish legitimate websites from spoofed websites. Most prior work focuses on assisting the user in making this distinction; however, users must make the right security decision every time. Unfortunately, humans are ill-suited for performing the security checks necessary for secure site identification, and a single mistake may result in a total compromise of the user's online account. Fundamentally, users should be authenticated using information that they cannot readily reveal to malicious parties. Placing less reliance on the user during the authentication process enhances security and eliminates many forms of fraud. We disclose using a trusted device to perform mutual authentication that eliminates reliance on perfect user behavior, thwarts Man-in-the-Middle attacks after setup, and protects a user's account even in the presence of keyloggers and most forms of spyware.
公开/授权文献
- US20100049975A1 Method and apparatus for secure online transactions 公开/授权日:2010-02-25
信息查询