首页> 外文期刊>ACM transactions on privacy and security >Formal Analysis of Mobile Multi-Factor Authentication with Single Sign-On Login
【24h】

Formal Analysis of Mobile Multi-Factor Authentication with Single Sign-On Login

机译:单一登录登录移动多因素身份验证的正式分析

获取原文
获取原文并翻译 | 示例
           

摘要

Over the last few years, there has been an almost exponential increase in the number of mobile applications that deal with sensitive data, such as applications for e-conunerce or health. When dealing with sensitive data, classical authentication solutions based on username-password pairs are not enough, and multi-factor authentication solutions that combine two or more authentication factors of different categories are required instead. Even if several solutions are currently used, their security analyses have been performed informally or semiformally at best, and without a reference model and a precise definition of the multi-factor authentication property. This makes a comparison among the different solutions both complex and potentially misleading. In this article, we first present the design of two reference models for native applications based on the requirements of two real-world use-case scenarios. Common features between them are the use of one-time password approaches and the support of a single sign-on experience. Then, we provide a formal specification of our threat model and the security goals, and discuss the automated security analysis that we performed. Our formal analysis validates the security goals of the two reference models we propose and provides an important building block for the formal analysis of different multi-factor authentication solutions.
机译:在过去几年中,处理敏感数据的移动应用程序数量几乎是指数增加,例如电子书内或健康的应用。在处理敏感数据时,基于用户名密码对的经典认证解决方案是不够的,而且需要组合两个或更多个认证因素的不同类别的多因素认证解决方案。即使当前使用了几种解决方案,它们的安全分析也是如此全面或半成正地执行,并且没有参考模型和多因素身份验证属性的精确定义。这在不同的解决方案中进行了比较,两者既复杂又潜在误导。在本文中,我们首先介绍了本机应用程序的两个参考模型的设计,基于两个真实用例场景的要求。它们之间的常见功能是使用一次性密码方法和支持单一登录体验。然后,我们提供了我们威胁模型和安全目标的正式规范,并讨论了我们执行的自动安全分析。我们的正式分析验证了我们提出的两个参考模型的安全目标,并为不同的多因素认证解决方案进行了正式分析的重要构建块。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号