首页> 外文会议>IEEE International Conference on Trust, Security and Privacy in Computing and Communications >Extending Registration and Authentication Processes of FIDO2 External Authenticator with QR Codes
【24h】

Extending Registration and Authentication Processes of FIDO2 External Authenticator with QR Codes

机译:使用QR码扩展FIDO2外部认证器的注册和认证过程

获取原文

摘要

FIDO2, the newest set of FIDO specifications, enables the user to leverage an external authenticator for the authentication in both mobile and desktop environments (referred to as user agent). For the secure registration and authentication, FIDO2 requires the external authenticator and user agent to establish a confidential and mutually authenticated data transport channel through either USB interfaces, Near Field Communication (NFC) or Bluetooth. However, the external authenticator and host may not be equipped with one of the above physical media simultaneously, for example, a desktop may only have USB interfaces while an external authenticator (e.g., a smartphone) may have no USB inferfaces. This affects the wide adoption of FIDO2. In this paper, we extend the registration and authentication processes of FIDO2 external authenticator with QR code, which enables the external authenticator being equipped with a camera to be used for the authentication at any user agent. During the registration process, our scheme requires the user to provide the original credential and a one-time password displayed on the authenticator, and therefore ensures the correct user will only be bound with the expected authenticator. The security of our scheme has been formally analyzed based on the Dolev-Yao style model, a widely adopted model for the analysis of web systems. We have implemented the prototype, and the performance evaluation demonstrated the efficiency of our scheme, which needs 373 ms for registration and 141 ms for authentication in our environment.
机译:Fido2是最新的Fido规范集,使用户能够利用外部验证器进行移动和桌面环境中的身份验证(称为用户代理)。有关安全注册和认证,FIDO2需要外部认证器和用户代理程序通过USB接口,近场通信(NFC)或蓝牙建立机密和相互认证的数据传输通道。然而,外部认证器和主机可以不同时配备上述物理媒体之一,例如,桌面可以仅具有USB接口,而外部认证器(例如,智能手机)可能没有USB接口备用空间。这影响了广泛采用的FIDO2。在本文中,我们使用QR码扩展了FIDO2外部认证器的注册和认证过程,该QR码使得外部认证器能够在任何用户代理中使用要用于认证的摄像机。在注册过程中,我们的方案要求用户提供验证器上显示的原始凭证和一次性密码,因此确保正确的用户只会与预期的认证器绑定。我们的计划的安全性已经基于Dolev-Yao风格模型,是Web系统分析的广泛采用的模型。我们已经实施了原型,绩效评估表明了我们的计划的效率,其中需要373 ms进行注册和141毫秒,以便在我们的环境中进行身份验证。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号