请输入您要查询的百科知识:

 

词条 Mutual authentication
释义

  1. See also

  2. References

  3. External links

{{Refimprove|date=July 2016}}

Mutual authentication or two-way authentication refers to two parties authenticating each other at the same time, being a default mode of authentication in some protocols (IKE, SSH) and optional in others (TLS).

By default the TLS protocol only proves the identity of the server to the client using X.509 certificate and the authentication of the client to the server is left to the application layer. TLS also offers client-to-server authentication using client-side X.509 authentication.[1] As it requires provisioning of the certificates to the clients and involves less user-friendly experience, it's rarely used in end-user applications.

Mutual TLS authentication (mTLS) is much more widespread in business-to-business (B2B) applications, where a limited number of programmatic and homogeneous clients are connecting to specific web services, the operational burden is limited and security requirements are usually much higher as compared to consumer environments.{{Quote|text = Better institution-to-customer authentication would prevent attackers from successfully impersonating financial institutions to steal customers' account credentials; and better customer-to-institution authentication would prevent attackers from successfully impersonating customers to financial institutions in order to perpetrate fraud|sign = Financial Services Technology Consortium, 2005|source =}}

Most Mutual authentication is machine-to-machine, leaving it up to chance whether or not users will notice (or care) when the remote authentication fails (e.g. a red address bar browser padlock, or a wrong domain name). Non-technical mutual-authentication also exists to mitigate this problem, requiring the user to complete a challenge, effectively forcing them to notice, and blocking them from authenticating with a false endpoint.

Mutual authentication is of two types:

  1. Certificate based
  2. User name-password based

See also

  • Computer security
  • Digital signature
  • Mobile signature
  • Pharming
  • Secure channel
  • Two-factor authentication

References

1. ^{{Cite web|url = https://tools.ietf.org/html/rfc5246#section-7.4.6|title = The Transport Layer Security (TLS) Protocol Version 1.2|last = |first = Tim Dierks|website = tools.ietf.org|access-date = 2016-04-22}}

External links

  • [https://docs.oracle.com/cd/E19798-01/821-1841/bncbt/index.html Two types of Mutual Authentication]
{{computer-security-stub}}

2 : Authentication methods|Computer access control

随便看

 

开放百科全书收录14589846条英语、德语、日语等多语种百科知识,基本涵盖了大多数领域的百科知识,是一部内容自由、开放的电子版国际百科全书。

 

Copyright © 2023 OENC.NET All Rights Reserved
京ICP备2021023879号 更新时间:2024/9/20 10:43:03