Article
Authentication by Encrypted Negative Password
Authors
Abstract
Its about securing the passwords and making the system more secured from intruders. Secure password storage is a vital aspect in systems based on password authentication, which is still the most widely used authentication technique, despite its some security flaws. Most e-commerce sites, consumers have the responsibility of creating their own passwords and often do so without guidance from the web site or system administrator. One fact is well known about password creation—consumers do not create long or complicated passwords because they cannot remember them. Most of the e-commerce sites uses the method where in the passwords are just encrypted and are not secured properly. In our project, we propose a password authentication framework that is designed for secure password. In our framework, first the received plain password from a client is hashed through a cryptographic hash function (Script and PBKDF2.)Then, the hashed password is converted into a negative password. Finally, the negative password is encrypted into an Encrypted Negative Password(ENP)(The cryptographic hash function and symmetric encryption make it difficult to crack passwords from ENPs. Moreover, there are lots of corresponding ENPs for a given plain password, which makes pre computation attacks (e.g., Brute Force Attack , Rainbow table attack and Dictionary attack) infeasible ENP) using a symmetric-key algorithm (e.g., AES), and multi-iteration encryption could be employed to further improve security.
Keywords
Citation
Published by: Engineering Journals


