SecureWeb: Protecting Sensitive Information Through the Web Browser Extension with a Security Token  被引量:3

SecureWeb: Protecting Sensitive Information Through the Web Browser Extension with a Security Token

在线阅读下载全文

作  者:Shuang Liang Yue Zhang Bo Li Xiaojie Guo Chunfu Jia Zheli Liu 

机构地区:[1]College of Cyberspace Security, Nankai University, Tianjin 300350, China [2]College of Cyberspace Security, Nankai University, Tianjin 300350 [3]Information Security Evaluation Center of Civil Aviation, Civil Aviation University of China, Tianjin 300300 [4]Key Lab on High Trusted Information System in Hebei Province, Baoding 071002, China

出  处:《Tsinghua Science and Technology》2018年第5期526-538,共13页清华大学学报(自然科学版(英文版)

基  金:supported by the National Key Basic Research Program of China (No. 2013CB834204);the National Natural Science Foundation of China (Nos. 61672300 and 61772291);the Natural Science Foundation of Tianjin, China (Nos. 16JCYBJC15500 and 17JCZDJC30500);the Open Project Foundation of Information Security Evaluation Center of Civil Aviation, and Civil Aviation University of China (No. CAACISECCA-201702)

摘  要:The leakage of sensitive data occurs on a large scale and with increasingly serious impact. It may cause privacy disclosure or even property damage. Password leakage is one of the fundamental reasons for information leakage, and its importance is must be emphasized because users are likely to use the same passwords for different Web application accounts. Existing approaches use a password manager and encrypted Web application to protect passwords and other sensitive data; however, they may be compromised or lack accessibility. The paper presents SecureWeb, which is a secure, practical, and user-controllable framework for mitigating the leakage of sensitive data. SecureWeb protects users' passwords and aims to provide a unified protection solution to diverse sensitive data. The efficiency of the developed schemes is demonstrated and the results indicate that it has a low overhead and are of practical use.The leakage of sensitive data occurs on a large scale and with increasingly serious impact. It may cause privacy disclosure or even property damage. Password leakage is one of the fundamental reasons for information leakage, and its importance is must be emphasized because users are likely to use the same passwords for different Web application accounts. Existing approaches use a password manager and encrypted Web application to protect passwords and other sensitive data; however, they may be compromised or lack accessibility. The paper presents SecureWeb, which is a secure, practical, and user-controllable framework for mitigating the leakage of sensitive data. SecureWeb protects users' passwords and aims to provide a unified protection solution to diverse sensitive data. The efficiency of the developed schemes is demonstrated and the results indicate that it has a low overhead and are of practical use.

关 键 词:password manager data privacy format-preserving encryption Shadow Document Object Model(DOM) 

分 类 号:TP393.09[自动化与计算机技术—计算机应用技术]

 

参考文献:

正在载入数据...

 

二级参考文献:

正在载入数据...

 

耦合文献:

正在载入数据...

 

引证文献:

正在载入数据...

 

二级引证文献:

正在载入数据...

 

同被引文献:

正在载入数据...

 

相关期刊文献:

正在载入数据...

相关的主题
相关的作者对象
相关的机构对象