会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 3. 发明授权
    • Method and apparatus for secure online transactions
    • 用于安全在线交易的方法和装置
    • US08352738B2
    • 2013-01-08
    • US11998890
    • 2007-12-03
    • Bryan ParnoCynthia KuoAdrian Perrig
    • Bryan ParnoCynthia KuoAdrian Perrig
    • H04L9/32G06Q20/00
    • H04L63/1441H04L63/08H04L63/1483H04L63/166
    • Phishing attacks succeed by exploiting a user's inability to distinguish legitimate websites from spoofed websites. Most prior work focuses on assisting the user in making this distinction; however, users must make the right security decision every time. Unfortunately, humans are ill-suited for performing the security checks necessary for secure site identification, and a single mistake may result in a total compromise of the user's online account. Fundamentally, users should be authenticated using information that they cannot readily reveal to malicious parties. Placing less reliance on the user during the authentication process enhances security and eliminates many forms of fraud. We disclose using a trusted device to perform mutual authentication that eliminates reliance on perfect user behavior, thwarts Man-in-the-Middle attacks after setup, and protects a user's account even in the presence of keyloggers and most forms of spyware.
    • 通过利用用户无法区分合法网站和欺骗性网站,网络钓鱼攻击成功。 大多数以前的工作侧重于协助用户做出这种区分; 然而,用户必须每次都做出正确的安全决定。 不幸的是,人类不适合执行安全站点识别所必需的安全检查,并且单个错误可能导致用户在线帐户的完全折中。 从根本上说,用户应该使用不能轻易向恶意方显露的信息进行身份验证。 在身份验证过程中,对用户的依赖程度越来越少,增强了安全性并消除了许多形式的欺诈。 我们披露使用受信任的设备执行相互身份验证,消除了对完美用户行为的依赖,在设置后阻止了中间人攻击,即使存在键盘记录程序和大多数形式的间谍软件,也可以保护用户的帐户。