DOI: 10.14489/vkit.2017.08.pp.003-008

Менщиков А. А., Комарова А. В., Гатчин Ю. А., Коробейников А. Г.
(c. 3-8)

Аннотация. Рассмотрены различные способы подтверждения доступа, начиная от простейших методов, основанных на использовании паролей, и заканчивая криптографической и биометрической аутентификациями. Проведен сравнительный анализ данных методов по основным характеристикам, в результате выявлен наиболее удобный в использовании, простой в реализации и безопасный метод. Сделаны соответствующие выводы о целесообразности использования того или иного способа при передаче данных в сети Интернет. Выявлено, что тенденции дальнейшего усовершенствования лежат в области гибридных систем с использованием криптографических алгоритмов.

Ключевые слова:  аутентификация; веб-ресурсы, веб-роботы; электронная цифровая подпись; криптография; биометрия; динамический пароль; двухфакторная аутентификация.


Menshchikov A. A., Komarova A. V., Gatchin Yu. A., Korobeynikov A. G.
(pp. 3-8)

Abstract. These days a huge amount of information is transferred and processed in computer networks. This information is often valuable, therefore it has to be protected. These days existing authentication mechanisms are imperfect. So, users need to understand which ones are suitable for each situation. To restrict third parties access to the information, it is important to carry out the authentication procedure. However, there is a security problem of the procedure on the web, due to insecure methods, based on a password. This paper discusses various ways to confirm an access, starting from the simplest methods based on the use of passwords, and ending with cryptographic and biometric authentication. Authors have analyzed different methods and publications and created a list of characteristics for methods comparison study. The comparative data analysis with basic method characteristics is provided. The most convenient to use, the easiest to implement and the most secure methods are found. Authors have taken every method and analyzed publications about their advantages and disadvantages according to characteristics. For each category different methods give different results which are shown in comparison tables. Moreover, to identify practical results, authors have performed a patent research on a given topic. It includes some international and Russian patent databases. Definite increase in the number of authentication related patents can also be noted over time. On the basis of the work authors made conclusions about the appropriateness of a particular data transmission method. It has been concluded that the subject of web authentication methods is relevant. The number of domestic developments is relatively low, which indicates a high prospect for further research. As a result, it is concluded that further improvements in the trends are in the field of hybrid systems. This leads to high demand for the new methods development, based on a combination of different approaches and new original algorithms using cryptography.

Keywords: Authentication; Web-resources; Web-robots; Electronic digital signature; Cryptography; Biometrics; Dynamic password; Two-factor authentication.


А. А. Менщиков, А. В. Комарова, Ю. А. Гатчин,  А. Г. Коробейников (Санкт-Петербургский национальный исследовательский университет информационных технологий, механики и оптики, Санкт-Петербург, Россия)  


A. A. Menshchikov, A. V. Komarova, Yu. A. Gatchin, A. G. Korobeynikov (Saint-Petersburg National Research University of Information Technologies, Mechanics and Optics, Saint-Petersburg, Russia)  


