Authentication in the Clouds: A Framework and its Application to Mobile Users

被引:61
作者
Chow, Richard [1 ]
Jakobsson, Markus [2 ]
Masuoka, Ryusuke [3 ]
Molina, Jesus [3 ]
Niu, Yuan [4 ]
Shi, Elaine [1 ]
Song, Zhexuan [3 ]
机构
[1] PARC, Palo Alto, CA 94304 USA
[2] FatSkunk, Mountain View, CA USA
[3] Fujitsu Labs Amer, Sunnyvale, CA USA
[4] Univ Calif Davis, Davis, CA USA
来源
PROCEEDINGS OF THE 2010 ACM WORKSHOP CLOUD COMPUTING SECURITY WORKSHOP (CCSW'10:) | 2010年
关键词
cloud computing; authentication; mobile computing;
D O I
10.1145/1866835.1866837
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Cloud computing is a natural fit for mobile security. Typical handsets have input constraints and practical computational and power limitations, which must be respected by mobile security technologies in order to be effective. We describe how cloud computing can address these issues. Our approach is based on a flexible framework for supporting authentication decisions we call TrustCube (to manage the authentication infrastructure) and on a behavioral authentication approach referred to as implicit authentication (to translate user behavior into authentication scores). The combination results in a new authentication paradigm for users of mobile technologies, one where an appropriate balance between usability and trust can be managed through flexible policies and dynamic tuning.
引用
收藏
页码:1 / 6
页数:6
相关论文
共 7 条
[1]  
[Anonymous], P 17 USENIX SEC S SE
[2]  
Greenstadt R., 2008, 1 ACM WORKSH AISEC
[3]  
Jakobsson Markus, 2009, HOTSEC 09
[4]  
Juels A., 2006, P 2006 IEEE S SEC PR
[5]  
Niu Y., 2010, USER WORKSH SOUPS
[6]  
Shi E., 2010, INF SEC C ISC
[7]  
Song Z., 2009, FUT TRUST COMP P 1 I