首页> 外文会议>IEEE International Conference on Anti-counterfeiting, Security, and Identification >A new secure authentication scheme for web login using BLE smart devices
【24h】

A new secure authentication scheme for web login using BLE smart devices

机译:使用BLE智能设备进行Web登录的新安全身份验证方案

获取原文

摘要

Existing user authentication schemes used for login to a website are incapable of handling recent phishing attacks such as real time (RT) / control relay (CR) man in the middle (MITM) attack and attacks launched via covertly installed malicious browser extensions (MEs). Two factor authentication schemes such as Google 2 Step verification, SAASPASS, QR code, graphical password and push notification based login schemes can be compromised using RT / CR MITM phishing attacks. Hardware token based schemes are safe but the extra cost of the hardware token makes them unattractive to users. Therefore, there is a need to develop new authentication schemes which are hard for an attacker to compromise but easy for users to understand and utilize. This paper analyzes existing authentication schemes to identify the research gaps and then proposes a secure authentication scheme which uses Bluetooth Low Energy (BLE, BT 4.0+ version) devices for user identification and which can handle RT/CR MITM phishing attacks, attacks launched via malicious browser extensions and app spoofing via attackers. The proposed scheme is location/client system independent and is secure from Bluetooth address spoofing attacks.
机译:用于登录网站的现有用户身份验证方案无法处理近期的网络钓鱼攻击,例如实时(RT)/中间控制中继(CR)人(MITM)攻击以及通过秘密安装的恶意浏览器扩展(ME)发起的攻击。可以使用RT / CR MITM网络钓鱼攻击来破坏两种因素的身份验证方案,例如Google两步验证,SAASPASS,QR码,图形密码和基于推送通知的登录方案。基于硬件令牌的方案是安全的,但是硬件令牌的额外成本使其对用户没有吸引力。因此,需要开发新的认证方案,攻击者难以妥协,但用户易于理解和利用。本文分析了现有的身份验证方案以识别研究差距,然后提出了一种安全的身份验证方案,该方案使用蓝牙低功耗(BLE,BT 4.0+版本)设备进行用户身份识别,并且可以处理RT / CR MITM网络钓鱼攻击,即通过恶意软件发起的攻击浏览器扩展程序和通过攻击者进行的应用程序欺骗。所提出的方案与位置/客户端系统无关,并且不受蓝牙地址欺骗攻击的影响。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号