English
Related papers

Related papers: How Not to Handle Keys: Timing Attacks on FIDO Aut…

200 papers

We consider the problem of identification and authentication based on secret key generation from some user-generated source data (e.g., a biometric source). The goal is to reliably identify users pre-enrolled in a database as well as…

Information Theory · Computer Science 2015-08-07 Kittipong Kittichokechai , Giuseppe Caire

Managing and exchanging sensitive information securely is a paramount concern for the scientific and cybersecurity community. The increasing reliance on computing workflows and digital data transactions requires ensuring that sensitive…

Cryptography and Security · Computer Science 2023-11-23 Md Jobair Hossain Faruk , Bilash Saha , Jim Basney

Besides cryptographic secrets, side-channel attacks also leak sensitive user input. The most accurate attacks exploit cache timings or interrupt information to monitor keystroke timings and subsequently infer typed words and sentences.…

Cryptography and Security · Computer Science 2017-06-21 Michael Schwarz , Moritz Lipp , Daniel Gruss , Samuel Weiser , Clémentine Maurice , Raphael Spreitzer , Stefan Mangard

Data security, which is concerned with the prevention of unauthorized access to computers, databases, and websites, helps protect digital privacy and ensure data integrity. It is extremely difficult, however, to make security watertight,…

Cryptography and Security · Computer Science 2018-01-03 Marten Lohstroh

Keyloggers remain a serious threat in modern cybersecurity, silently capturing user keystrokes to steal credentials and sensitive information. Traditional defenses focus mainly on detection and removal, which can halt malicious activity but…

Cryptography and Security · Computer Science 2025-08-07 Md Sajidul Islam Sajid , Shihab Ahmed , Ryan Sosnoski

Continuous authentication has been proposed as a complementary security mechanism to password-based authentication for computer devices that are handled directly by humans, such as smart phones. Continuous authentication has some privacy…

Cryptography and Security · Computer Science 2022-09-15 Sigurd Eskeland , Ahmed Fraz Baig

In big data systems, the infrastructure is such that large amounts of data are hosted away from the users. In such a system information security is considered as a major challenge. From a customer perspective, one of the big risks in…

Cryptography and Security · Computer Science 2016-12-07 Santosh Aditham , Nagarajan Ranganathan

Digital transformation with the adoption of cloud technologies, outsourcing, and working-from-home possibilities permits flexibility for organizations and persons. At the same time, it makes it more difficult to secure the IT infrastructure…

Cryptography and Security · Computer Science 2024-07-25 Daniela Pöhn , Wolfgang Hommel

Fingerprint traits are widely recognized for their unique qualities and security benefits. Despite their extensive use, fingerprint features can be vulnerable to puppet attacks, where attackers manipulate a reluctant but genuine user into…

Computer Vision and Pattern Recognition · Computer Science 2023-11-20 Wenhao Wang , Guyue Li , Zhiming Chu , Haobo Li , Daniele Faccio

A major security challenge for modern Internet of Things (IoT) deployments is to ensure that the devices run legitimate firmware free from malware. This challenge can be addressed through a security primitive called attestation which allows…

Cryptography and Security · Computer Science 2022-01-31 Stefan Hristozov , Moritz Wettermann , Manuel Huber

Many tracking companies collect user data and sell it to data markets and advertisers. While they claim to protect user privacy by anonymizing the data, our research reveals that significant privacy risks persist even with anonymized data.…

Cryptography and Security · Computer Science 2026-02-12 Ruisheng Shi , Zhiyuan Peng , Tong Fu , Lina Lan , Qin Wang , Jiaqi Zeng

Privacy of users in P2P networks goes far beyond their current usage and is a fundamental requirement to the adoption of P2P protocols for legal usage. In a climate of cold war between these users and anti-piracy groups, more and more users…

Networking and Internet Architecture · Computer Science 2010-04-12 Pere Manils , Chaabane Abdelberri , Stevens Le Blond , Mohamed Ali Kaafar , Claude Castelluccia , Arnaud Legout , Walid Dabbous

Static and hard-coded layer-two network identifiers are well known to present security vulnerabilities and endanger user privacy. In this work, we introduce a new privacy attack against Wi-Fi access points listed on secondhand marketplaces.…

Cryptography and Security · Computer Science 2025-06-24 Steven Su , Erik Rye , Dave Levin , Robert Beverly

Anonymous data collection systems allow users to contribute the data necessary to build services and applications while preserving their privacy. Anonymity, however, can be abused by malicious agents aiming to subvert or to sabotage the…

Cryptography and Security · Computer Science 2018-12-20 Alex Catarineu , Philipp Claßen , Konark Modi , Josep M. Pujol

Trigger-Action platforms are an emerging class of web-based systems that enable users to create automation rules (or recipes) of the form, "If there is a smoke alarm, then turn off my oven." These platforms stitch together various online…

Cryptography and Security · Computer Science 2017-07-04 Earlence Fernandes , Amir Rahmati , Jaeyeon Jung , Atul Prakash

Keystroke timing based active authentication systems are conceptually attractive because: (i) they use the keyboard as the sensor and are not hardware-cost prohibitive, and (ii) they use the keystrokes generated from normal usage of…

Cryptography and Security · Computer Science 2018-04-24 Md Enamul Karim , Kiran S. Balagani , Aaron Elliott , David Irakiza , Mike O'Neal , Vir Phoha

Relay attacks are a major concern for RFID systems: during an authentication process an adversary transparently relays messages between a verifier and a remote legitimate prover. We present an authentication protocol suited for RFID…

Cryptography and Security · Computer Science 2008-09-25 Gildas Avoine , Aslan Tchamkerten

Many terminals are used in safety-critical operations in which humans, through terminal user interfaces, become a part of the system control loop (e.g., medical and industrial systems). These terminals are typically embedded, single-purpose…

Cryptography and Security · Computer Science 2016-04-19 Luka Malisa , Kari Kostiainen , Thomas Knell , David Sommer , Srdjan Capkun

The advancement of computing equipment and the advances in services over the Internet has allowed corporations, higher education, and many other organizations to pursue the shared computing network environment. A requirement for shared…

Cryptography and Security · Computer Science 2025-08-19 Tyler Schroder , Sohee Kim Park

Approximately 61% of cyber attacks involve adversaries in possession of valid credentials. Attackers acquire credentials through various means, including phishing, dark web data drops, password reuse, etc. Multi-factor authentication (MFA)…

Cryptography and Security · Computer Science 2024-08-31 Sam Hays , Michael Sandborn , Jules White