English
Related papers

Related papers: How Not to Handle Keys: Timing Attacks on FIDO Aut…

200 papers

Although sufficient authentication mechanisms were enhanced by the use of two or more factors that resulted in new multi factor authentication schemes, more sophisticated and targeted attacks have shown they are also vulnerable. This…

Continuous Authentication (CA) has been proposed as a potential solution to counter complex cybersecurity attacks that exploit conventional static authentication mechanisms that authenticate users only at an ingress point. However, widely…

Cryptography and Security · Computer Science 2020-10-13 Syed W. Shah , Naeem F. Syed , Arash Shaghaghi , Adnan Anwar , Zubair Baig , Robin Doss

Authentication based on keystroke dynamics is a convenient biometric approach, easy in use, transparent, and cheap as it does not require a dedicated sensor. Keystroke authentication, as part of multi factor authentication, can be used in…

Cryptography and Security · Computer Science 2020-12-08 Ievgeniia Kuzminykh , Bogdan Ghita , Alexandr Silonosov

This paper discusses that there is significant benefit in providing stronger security at lower layers of the network stack for hosts connected to a network. It claims to reduce the attack vulnerability of a networked host by providing…

Networking and Internet Architecture · Computer Science 2008-12-18 Arun Kumar S P

We propose a two-factor authentication (2FA) mechanism called 2D-2FA to address security and usability issues in existing methods. 2D-2FA has three distinguishing features: First, after a user enters a username and password on a login…

Cryptography and Security · Computer Science 2021-11-01 Maliheh Shirvanian , Shashank Agrawal

Designing an efficient protocol for avoiding the threat of recording based attack in presence of a powerful eavesdropper remains a challenge for more than two decades. During authentication, the absence of any secure link between the prover…

Cryptography and Security · Computer Science 2017-05-31 Nilesh Chakraborty , Samrat Mondal

Identity authentication is the process of verifying one's identity. There are several identity authentication methods, among which biometric authentication is of utmost importance. Facial recognition is a sort of biometric authentication…

Computer Vision and Pattern Recognition · Computer Science 2022-12-15 Matineh Pooshideh

In this paper we discuss the difficulties of mounting successful attack against crypto implementations when essential information is missing. We start with a detailed description of our attack against our own design, to highlight which…

Cryptography and Security · Computer Science 2022-01-25 Ievgen Kabin , Zoya Dyka , Dan Klann , Jan Schaeffner , Peter Langendoerfer

This paper proposes the first user-independent inter-keystroke timing attacks on PINs. Our attack method is based on an inter-keystroke timing dictionary built from a human cognitive model whose parameters can be determined by a small…

Cryptography and Security · Computer Science 2018-10-18 Ximing Liu , Yingjiu Li , Robert H. Deng , Bing Chang , Shujun Li

This paper describes a new protocol for authentication in ad-hoc networks. The protocol has been designed to meet specialized requirements of ad-hoc networks, such as lack of direct communication between nodes or requirements for revocable…

Cryptography and Security · Computer Science 2007-05-23 Adam Wierzbicki , Aneta Zwierko , Zbigniew Kotulski

The Third Generation Partnership Project (3GPP) released its first 5G security specifications in March 2018. This paper reviews the 5G security architecture, requirements and main processes and evaluates them in the context of known and new…

Cryptography and Security · Computer Science 2018-11-30 Roger Piqueras Jover , Vuk Marojevic

Emerging technology demands reliable authentication mechanisms, particularly in interconnected systems. Current systems rely on a single moment of authentication, however continuous authentication systems assess a users identity utilizing a…

Cryptography and Security · Computer Science 2019-03-11 Rasana Manandhar , Shaya Wolf , Mike Borowczak

This paper investigates the secret key authentication capacity region. Specifically, the focus is on a model where a source must transmit information over an adversary controlled channel where the adversary, prior to the source's…

Information Theory · Computer Science 2020-01-07 Eric Graves , Jake Perazzone , Paul Yu , Rick Blum

Ephemeral Diffie-Hellman Over COSE (EDHOC) aims at being a very compact and lightweight authenticated Diffie-Hellman key exchange with ephemeral keys. It is expected to provide mutual authentication, forward secrecy, and identity…

Cryptography and Security · Computer Science 2022-09-12 Baptiste Cottier , David Pointcheval

With the rapid advancement of wireless network technology, usage of WSN in real time applications like military, forest monitoring etc. found increasing. Generally WSN operate in an unattended environment and handles critical data.…

Cryptography and Security · Computer Science 2013-11-14 Chandra Sekhar Vorugunti , Mrudula Sarvabhatla

Credential stuffing attacks use stolen passwords to log into victim accounts. To defend against these attacks, recently deployed compromised credential checking (C3) services provide APIs that help users and companies check whether a…

Cryptography and Security · Computer Science 2022-03-25 Bijeeta Pal , Mazharul Islam , Marina Sanusi , Nick Sullivan , Luke Valenta , Tara Whalen , Christopher Wood , Thomas Ristenpart , Rahul Chattejee

Many millions of users routinely use their Google, Facebook and Microsoft accounts to log in to websites supporting OAuth 2.0 and/or OpenID Connect-based single sign on. The security of OAuth 2.0 and OpenID Connect is therefore of critical…

Cryptography and Security · Computer Science 2018-01-25 Wanpeng Li , Chris J Mitchell , Thomas Chen

Recently, the IaaS (Infrastructure as a Service) Cloud (e.g., Amazon EC2) has been widely used by many organizations. However, some IaaS security issues create serious threats to its users. A typical issue is the timing channel. This kind…

Cryptography and Security · Computer Science 2018-04-06 Xiao Fu , Rui Yang , Xiaojiang Du , Bin Luo

Time-based one-time password (TOTP) systems in use today require storing secrets on both the client and the server. As a result, an attack on the server can expose all second factors for all users in the system. We present T/Key, a…

Cryptography and Security · Computer Science 2017-08-29 Dmitry Kogan , Nathan Manohar , Dan Boneh

We study the security of a specific authentication procedure of interest in the context of Quantum Key Distribution (QKD). It works as follows: use a secret but fixed Strongly Universal$_2$ (SU$_2$) hash function and encrypt the output tag…

Quantum Physics · Physics 2011-09-26 Aysajan Abidin , Jan-Åke Larsson