Repository logo

CredProxy: A Password Manager for Online Authentication Environments

dc.contributor.authorGolrang, Mohammad Saleh
dc.contributor.supervisorAdams, Carlisle
dc.date.accessioned2012-12-20T21:33:33Z
dc.date.available2012-12-20T21:33:33Z
dc.date.created2013
dc.date.issued2013
dc.degree.disciplineGénie / Engineering
dc.degree.levelmasters
dc.degree.nameMSc
dc.description.abstractInternet users are increasingly required to sign up for online services and establish accounts before receiving service from websites. On the one hand, generation of strong usernames and passwords is a difficult task for the user. On the other hand, memorization of strong passwords is by far more problematic for the average user. Thus, the average user has a tendency to use weak passwords, and also reuse his passwords for more than one website, which makes several attacks feasible. Under the aforementioned circumstances, the use of password managers is beneficial, since they unburden the user from the task of memorizing user credentials. However, password managers have a number of weaknesses. This thesis is mainly aimed at alleviating some of the intrinsic weaknesses of password managers. We propose three cryptographic protocols which can improve the security of password managers while enhancing user convenience. We also present the design of a phishing and Man-in-the-Browser resistant password manger which best fits into our scheme. Furthermore, we present our novel virtual on-screen keyboard and keypad which are designed to provide strong protection mechanisms against threats such as keylogging and shoulder surfing.
dc.embargo.termsimmediate
dc.faculty.departmentInformatique / Computer Science
dc.identifier.urihttp://hdl.handle.net/10393/23611
dc.identifier.urihttp://dx.doi.org/10.20381/ruor-6391
dc.language.isoen
dc.publisherUniversité d'Ottawa / University of Ottawa
dc.subjectDictionary Attacks
dc.subjectPassword Managers
dc.subjectPassword Security
dc.subjectWebsite User Authentication
dc.subjectVirtual Keyboards
dc.subjectMITB Attacks
dc.titleCredProxy: A Password Manager for Online Authentication Environments
dc.typeThesis
thesis.degree.disciplineGénie / Engineering
thesis.degree.levelMasters
thesis.degree.nameMSc
uottawa.departmentInformatique / Computer Science

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail ImageThumbnail Image
Name:
Golrang_Mohammad_Saleh_2012_Thesis.pdf
Size:
2.02 MB
Format:
Adobe Portable Document Format

License bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail ImageThumbnail Image
Name:
license.txt
Size:
4.21 KB
Format:
Item-specific license agreed upon to submission
Description: