Journal of Information Security Reserach ›› 2024, Vol. 10 ›› Issue (12): 1128-.

Previous Articles     Next Articles

A Securityenhanced Circular Text CAPTCHA

Gao Jiahua1, Ren Yawei1, and Ye Ming2   

  1. 1(Information Management Institute, Beijing Information Science and Technology University, Beijing 100192)
    2(Research Institute of Petroleum Exploration & Development, Beijing 100083)
  • Online:2024-12-25 Published:2024-12-25

一种安全性增强的环形文本验证码

郜佳华1任亚唯1叶铭2   

  1. 1(北京信息科技大学信息管理学院北京100192)
    2(中国石油勘探开发研究院北京100083)
  • 通讯作者: 任亚唯 博士,副教授.主要研究方向为密码学、网络安全. ryw@bistu.edu.cn
  • 作者简介:郜佳华 硕士.主要研究方向为视觉密码. 1179289917@qq.com 任亚唯 博士,副教授.主要研究方向为密码学、网络安全. ryw@bistu.edu.cn 叶铭 硕士,高级工程师.主要研究方向为信息化基础设施规划、网络安全. yeming@petrochina.com.cn

Abstract: To counteract malicious activities and automated programs attempting to infiltrate and attack websites or systems, a secure circular textbased CAPTCHA is designed based on a multisecret visual cryptography. In this approach, multiple circular secret images are randomly generated by the serverside and encrypted into two circular share images, one of the share images is saved while the other is distributed to the user. When the server receives a login request from the user, the shared image submitted by the user and the circular share image saved on the server are rotated and overlapped to recover the secret image. Random characters are then dynamically selected from each secret image to generate a circular CAPTCHA, enhancing the authentication function for legitimate users and providing more effective resistance to phishing attacks. Following CAPTCHA image quality assessment and recognition situation consideration, the circular textbased CAPTCHA ensures usability while significantly enhancing security, offering strong support for website and system protection.

Key words: CAPTCHA, secret sharing, multisecret visual cryptography, CAPTCHA recognition, Web pishing

摘要: 为了抵御恶意行为和自动化程序对网站或系统的侵入和攻击,采用了多秘密视觉密码方案设计一种安全性增强的环形文本验证码,即通过服务器端随机生成多个环形秘密图像,将它们加密成2个环形分享图像,并保存其中的一个分享图像,将另一个分享图像分发给用户.服务器收到用户的登录请求后,将用户提交的分享图像和其保存的环形分享图像进行旋转和叠加后恢复出秘密图像,并从每个秘密图像中随机选取字符动态生成环形验证码,增强了对合法用户的身份认证功能,能够更有效地抵御钓鱼攻击.经过验证码图像质量评估和识别情况的考量,环形文本验证码在确保可用性的同时也显著提升了安全性,为网站和系统的保护提供了有力支持.

关键词: 验证码, 秘密共享, 多秘密视觉密码, 验证码识别, 网站钓鱼

CLC Number: