钥匙(锁)
计算机科学
密码学
计算机硬件
嵌入式系统
发电机(电路理论)
硬件安全模块
密钥管理
密码协议
密码原语
计算机安全
功率(物理)
量子力学
物理
作者
Malik Hamza Murtaza,Hasan Tahir,Shahzaib Tahir,Zahoor Ahmed Alizai,Qaiser Riaz,Mehdi Hussain
标识
DOI:10.1016/j.jisa.2022.103332
摘要
It has been noted with concern that the ability of a password to keep an information system secure is diminishing. Increasingly sophisticated attack vectors and low memorability associated with complicated passwords are among the leading reasons limiting security provisioned by passwords. Cryptographic keys suffer from issues including lack of memorability, vulnerable storage mechanisms, key retrieval attacks, lockouts due to key loss and risk of using the same key for multiple services. This study proposes a novel Hardware Security Module (HSM) as a basis for the generation/ re-creation of cryptographic keys. The designed hardware module entirely eliminates the stored cryptographic keys thus eliminating attacks against stored keys. The HSM derives the cryptographic key from sub-components behaving similar to multi-factor authentication, where each factor is an independent authenticator. The proposed scheme enhances security by incorporating physical security into digital security, i.e. as long as either the crypto provider device remains secure or the human component remains secure, the system security remains intact. The scheme proposes a strategy based on defense in depth to secure the HSM, its user, the related service from attacks ranging from simple shoulder surfing to sophisticated Man-in-the-Middle attacks. The proposed HSM is based on commodity hardware components thus having limited cost implications.
科研通智能强力驱动
Strongly Powered by AbleSci AI