错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

A Non-interactive One-Time Password-Based Method to Enhance the Vault Security

  • Juarez Oliveira,
  • Altair Santin,
  • Eduardo Viegas,
  • Pedro Horchulhack

摘要

Multi-factor authentication (MFA) is recommended to access sensitive data applications. A password Vault protects secrets by storing privileged user credentials and access codes. The combination of MFA and Trusted Execution Environment (TEE) by multiple communication channels reduces the attack surface of secrets and enables secure periodic code updates from the password Vault. In this paper, we propose all these layers of protection and add a one-time password (OTP) mechanism to enhance the security of the Vault without human intervention. The expiration time of the code in the Vault remains unchanged. Finally, we show that web applications and an interactive remote shell are effectively secured by penetration testing from an adversary’s point of view.