About: RSA SecurID is a research topic. Over the lifetime, 6 publications have been published within this topic receiving 14 citations. The topic is also known as: RSA SecurID.
TL;DR: The resulting harms of a successful attack against such firms are not limited to information losses and mitigation expenses; the attacks may undermine the very reputations of the firms.
Abstract: I. INTRODUCTION II. BACKGROUND A. EMC Corporation and the RSA SecurID Token Hack B. Magnitude of the Threat to Corporations and Their Investors C. SEC Disclosure Requirements D. Senator Rockefeller's Letter E. SEC's October 2011 Disclosure Guidelines III. ANALYSIS A. Disclosure Obligations Under the Guidelines 1. Risk Factors 2. Management's Discussion and Analysis of Financial Condition and Results of Operations (MDA in fact, for some, "security" is their business. (9) Others, though not in the security business, are considered leaders in the information technology, computer networking, and Internet business fields. (10) The resulting harms of a successful attack against such firms are not limited to information losses and mitigation expenses; the attacks may undermine the very reputations of the firms. …
TL;DR: It is shown that if a user happens to log in to a server from a terminal that has been fully compromised, then the other past and future user's sessions initiated from honest terminals stay secure and the first user authentication and key exchange protocols that can tolerate strong corruptions on the client-side are proposed.
Abstract: We propose the first user authentication and key exchange protocols that can tolerate strong corruptions on the client-side. If a user happens to log in to a server from a terminal that has been fully compromised, then the other past and future user's sessions initiated from honest terminals stay secure. We define the security model for Human Authenticated Key Exchange HAKE) protocols and first propose two generic protocols based on human-compatible (HC) function family, password-authenticated key exchange (PAKE), commitment, and authenticated encryption. We prove our HAKE protocols secure under reasonable assumptions and discuss efficient instantiations. We thereafter propose a variant where the human gets help from a small device such as RSA SecurID. This permits to implement an HC function family with stronger security and thus allows to weaken required assumptions on the PAKE. This leads to the very efficient HAKE which is still secure in case of strong corruptions. We believe that our work will promote further developments in the area of human-oriented cryptography.
TL;DR: Five typical cases of advanced persistent threat including Night Dragon attack, Google Operation Aurora, RSA SecurID attack, Stuxnet attack and Shady Rat attack were analyzed and some suggestions and opinions on secrutiy protection were presented.
Abstract: Advanced persistent threat (APT) has become a serious chanllenge to network security in recent yeas. Characteristics of this kind of network attack involve purposiveness,concealment,sustainability and variability, and it is hard to protect for critical infrastructure, financial systems, elements of national power, etc. These threats range from unwitting hackers to nation-states, each at various levels of competence. For performing security protection, five typical cases of APT including Night Dragon attack, Google Operation Aurora, RSA SecurID attack, Stuxnet attack and Shady Rat attack were analyzed. Its commonly attack process and technology characteristics are summarized. Finally, some suggestions and opinions on secrutiy protection were presented.
TL;DR: In this paper, the authors define the security model for Human Authenticated Key Exchange (HAKE) protocols and propose two generic protocols based on human compatible function family, password-authenticated key exchange (PAKE), commitment, and authenticated encryption.
Abstract: We propose the first user authentication and key exchange protocols that can tolerate strong corruptions on the client-side. If a user happens to log in to a server from a terminal that has been fully compromised, then the other past and future user's sessions initiated from honest terminals stay secure. We define the security model for Human Authenticated Key Exchange HAKE) protocols and first propose two generic protocols based on human-compatible (HC) function family, password-authenticated key exchange (PAKE), commitment, and authenticated encryption. We prove our HAKE protocols secure under reasonable assumptions and discuss efficient instantiations. We thereafter propose a variant where the human gets help from a small device such as RSA SecurID. This permits to implement an HC function family with stronger security and thus allows to weaken required assumptions on the PAKE. This leads to the very efficient HAKE which is still secure in case of strong corruptions. We believe that our work will promote further developments in the area of human-oriented cryptography.
TL;DR: A new access control mechanism based on port knocking techniques and its integration into EFDA-Federation is developed, and federated organisations are able to offer SecurID to their users as an alternative strong authentication mechanism, with the corresponding increase of security level.