首页> 外文期刊>Concurrency, practice and experience >Securing PIN-based authentication in smartwatches with just two gestures
【24h】

Securing PIN-based authentication in smartwatches with just two gestures

机译:只需两个手势,在SmartWatches中确保基于密码的身份验证

获取原文
获取原文并翻译 | 示例

摘要

Smartwatches are becoming increasingly ubiquitous as they offer new capabilities to develop sophisticated applications that make daily life easier and more convenient for consumers. The services provided include applications for mobile payment, ticketing, identification, access control, etc. While this makes modern smartwatches very powerful devices, it also makes them very attractive targets for attackers. Indeed, PINs and Pattern Lock have been widely used in smartwatches for user authentication. However, such authentication methods are not robust against various forms of cybersecurity attacks, such as side channel, phishing, smudge, shoulder surfing, and video-recording attacks. Moreover, the recent adoption of hardware-based solutions, like the Trusted Execution Environment (TEE), can mitigate only partially such problems. Thus, the user's security and privacy are at risk without a strong authentication scheme in place. In this work, we propose 2GesturePIN, a new authentication framework that allows users to authenticate securely to their smartwatches and related sensitive services through solely two gestures. 2GesturePIN leverages the rotating bezel or crown, which are the most intuitive ways to interact with a smartwatch, as a dedicated hardware. 2GesturePIN improves the resilience of the regular PIN authentication method against state-of-the-art cybersecurity attacks while maintaining a high level of usability.
机译:SmartWatches正在越来越普遍存在,因为它们提供了开发精致的应用程序,使日常生活更容易,更方便消费者的产品。提供的服务包括移动支付,票务,识别,访问控制等的申请,同时这使得现代SmartWatches非常强大的设备,它也使它们具有非常有吸引力的攻击者目标。实际上,引脚和模式锁已广泛用于用户身份验证的SmartWatch。然而,这种认证方法对针对各种形式的网络安全攻击不稳定,例如侧通道,网络钓鱼,涂抹,肩部冲浪和视频记录攻击。此外,最近采用基于硬件的解决方案,如可信任的执行环境(TEE),只能局部减轻这样的问题。因此,如果没有强大的认证方案,用户的安全性和隐私则处于危险之中。在这项工作中,我们提出了2份措施,这是一个新的身份验证框架,允许用户通过单独使用两个手势安全地对其SmartWatches和相关的敏感服务进行认证。 2Gesturepin利用旋转边框或冠,这是与SmartWatch相互作用的最直观的方式,作为专用硬件。 2Gesturepin改善了常规引脚认证方法的恢复力,以防止最先进的网络安全攻击,同时保持高水平的可用性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号