English
Related papers

Related papers: TUSH-Key: Transferable User Secrets on Hardware Ke…

200 papers

Embedded systems play a crucial role in fueling the growth of the Internet-of-Things (IoT) in application domains such as healthcare, home automation, transportation, etc. However, their increasingly network-connected nature, coupled with…

Cryptography and Security · Computer Science 2017-12-06 Soubhagya Sutar , Arnab Raha , Vijay Raghunathan

Despite being more secure and strongly promoted, two-factor (2FA) or multi-factor (MFA) schemes either fail to protect against recent phishing threats such as real-time MITM, controls/relay MITM, malicious browser extension-based phishing…

Cryptography and Security · Computer Science 2024-06-14 Sneha Shukla , Gaurav Varshney , Shreya Singh , Swati Goel

Existing fuzzy extractors and similar methods provide an effective way for extracting a secret key from a user's biometric data, but are susceptible to impersonation attack: once a valid biometric sample is captured, the scheme is no longer…

Cryptography and Security · Computer Science 2024-05-21 Hong Yen Tran , Jiankun Hu , Wen Hu

With the rise of decentralized finance, fiat-to-cryptocurrency exchange platforms have become popular entry points into the cryptocurrency ecosystem. However, these platforms frequently fail to ensure adequate privacy protection, as…

Cryptography and Security · Computer Science 2026-01-26 Shaoyu Li , Hexuan Yu , Md Mohaimin Al Barat , Yang Xiao , Y. Thomas Hou , Wenjing Lou

The majority of current web authentication is built on username/password. Unfortunately, password replacement offers more security, but it is difficult to use and expensive to deploy. In this paper, we propose a new mutual authentication…

Cryptography and Security · Computer Science 2014-12-10 Yassine Sadqi , Ahmed Asimi , Younes Asimi

Preservation of information and computer security is broadly dependent on the secured authentication system which is underpinned by password. Text based password is a commonly used and available system for authentication. But it bears many…

Cryptography and Security · Computer Science 2022-05-26 Sanjida Akter Sharna , Sheikh Ashraf Ali

In its current state, the Internet does not provide end users with transparency and control regarding on-path forwarding devices. In particular, the lack of network device information reduces the trustworthiness of the forwarding path and…

Networking and Internet Architecture · Computer Science 2023-10-12 Cyrill Krähenbühl , Marc Wyss , David Basin , Vincent Lenders , Adrian Perrig , Martin Strohmeier

Functional encryption introduces a new paradigm of public key encryption that decryption only reveals the function value of encrypted data. To curb key leakage issues and trace users in FE-IP, a new primitive called traceable functional…

Cryptography and Security · Computer Science 2024-04-16 Muyao Qiu , Jinguang Han

Electronic Identification (eID) is becoming commonplace in several European countries. eID is typically used to authenticate to government e-services, but is also used for other services, such as public transit, e-banking, and physical…

Cryptography and Security · Computer Science 2014-09-10 Thomas Nyman , Jan-Erik Ekberg , N. Asokan

We present a theoretical framework for the analysis of privacy and security tradeoffs in secure biometric authentication systems. We use this framework to conduct a comparative information-theoretic analysis of two biometric systems that…

Information Theory · Computer Science 2011-12-26 Ye Wang , Shantanu Rane , Stark C. Draper , Prakash Ishwar

We propose a framework by which websites can coordinate to detect credential stuffing on individual user accounts. Our detection algorithm teases apart normal login behavior (involving password reuse, entering correct passwords into the…

Cryptography and Security · Computer Science 2021-03-05 Ke Coby Wang , Michael K. Reiter

Recently, Yang and Tan proposed a certificateless key exchange protocol without pairing, and claimed their scheme satisfies forward secrecy, which means no adversary could derive an already-established session key unless the full user…

Cryptography and Security · Computer Science 2011-12-06 Min Zhang , Jie Zhang , Qiao-Yan Wen , Zheng-Ping Jin , Hua Zhang

Most of the security services in the connected world of cyber-physical systems necessitate authenticating a large number of nodes privately. In this paper, the private authentication problem is considered which consists of a certificate…

Information Theory · Computer Science 2022-09-13 Narges Kazempour , Mahtab Mirmohseni , Mohammad Reza Aref

The paper presents a step forward in the design and implementation of a Transport Layer Security (TLS) handshake protocol that enables the use of Verifiable Credential (VC) while maintaining full compliance with RFC-8446 and preserving all…

Cryptography and Security · Computer Science 2025-05-22 Leonardo Perugini , Andrea Vesco

We present True2F, a system for second-factor authentication that provides the benefits of conventional authentication tokens in the face of phishing and software compromise, while also providing strong protection against token faults and…

Cryptography and Security · Computer Science 2019-08-13 Emma Dauterman , Henry Corrigan-Gibbs , David Mazières , Dan Boneh , Dominic Rizzo

The erosion of trust put in traditional database servers, the growing interest for different forms of data dissemination and the concern for protecting children from suspicious Internet content are different factors that lead to move the…

Cryptography and Security · Computer Science 2007-05-23 Luc Bouganim , Cosmin Cremarenco , François Dang Ngoc , Nicolas Dieu , Philippe Pucheral

Tools that synchronize passwords over several user devices typically store the encrypted passwords in a central online database. For encryption, a low-entropy, password-based key is used. Such a database may be subject to unauthorized…

Cryptography and Security · Computer Science 2015-06-16 Moritz Horsch , Andreas Hülsing , Johannes Buchmann

Smartphones are now frequently used by end-users as the portals to cloud-based services, and smartphones are easily stolen or co-opted by an attacker. Beyond the initial log-in mechanism, it is highly desirable to re-authenticate end-users…

Cryptography and Security · Computer Science 2017-03-13 Wei-Han Lee , Ruby Lee

Hardware Security Modules (HSMs) are trusted machines that perform sensitive operations in critical ecosystems. They are usually required by law in financial and government digital services. The most important feature of an HSM is its…

Cryptography and Security · Computer Science 2021-09-29 Riccardo Focardi , Flaminia L. Luccio

This paper provides a proof of concept for using SRAM based Physically Unclonable Functions (PUFs) to generate private keys for IoT devices. PUFs are utilized, as there is inadequate protection for secret keys stored in the memory of the…

Cryptography and Security · Computer Science 2019-07-30 Ashwija Reddy Korenda , Fatemeh Afghah , Bertrand Cambou , Christopher Philabaum