【24h】

Defending against device theft with human notarization

机译:通过公证来防御设备盗窃

获取原文

摘要

People increasingly rely on mobile phones for storing sensitive information and credentials for access to services. Because these devices are vulnerable to theft, security of this data is put at higher risk-once the attacker is in physical possession of the device, recovering these credentials and impersonating the owner of the phone is hard to defend by purely local means. We introduce the concept of `notarization', a process by which a remote notary verifies the identity of the device user through video chat. We describe the design and implementation of a system that leverages notarization to protect cryptographic keys that the device uses to decrypt device data (e.g., website passwords) or perform signatures in support of client-side TLS, without trusting the notary with these keys. Through a lab-based study with 56 participants, we show that notarization even by strangers is effective for combating device theft.
机译:人们越来越依赖于移动电话来存储敏感信息和凭据以访问服务。由于这些设备容易遭到盗窃,一旦攻击者实际拥有该设备,就将使这些数据的安全性面临更高的风险,因此很难通过纯粹的本地手段来保护这些凭证并冒充手机所有者。我们介绍“公证”的概念,远程公证员通过视频聊天来验证设备用户的身份。我们描述了一种系统的设计和实现,该系统利用公证来保护设备用来解密设备数据(例如网站密码)或执行签名以支持客户端TLS的加密密钥,而不用这些密钥来信任公证人。通过对56位参与者进行的基于实验室的研究,我们表明,即使是陌生人的公证也可以有效地防止设备失窃。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号