中文
相关论文

相关论文: CTRAPS: CTAP Client Impersonation and API Confusio…

200 篇论文

This paper presents a timing attack on the FIDO2 (Fast IDentity Online) authentication protocol that allows attackers to link user accounts stored in vulnerable authenticators, a serious privacy concern. FIDO2 is a new standard specified by…

密码学与安全 · 计算机科学 2022-05-18 Michal Kepkowski , Lucjan Hanzlik , Ian Wood , Mohamed Ali Kaafar

Web authentication is a critical component of today's Internet and the digital world we interact with. The FIDO2 protocol enables users to leverage common devices to easily authenticate to online services in both mobile and desktop…

密码学与安全 · 计算机科学 2023-06-22 Wei-Zhu Yeoh , Michal Kepkowski , Gunnar Heide , Dali Kaafar , Lucjan Hanzlik

FIDO2 authentication is starting to be applied in numerous web authentication services, aiming to replace passwords and their known vulnerabilities. However, this new authentication method has not been integrated yet with network…

密码学与安全 · 计算机科学 2024-04-29 Martiño Rivera-Dourado , Marcos Gestal , Alejandro Pazos , Jose Vázquez-Naya

With the rise of attacks on online accounts in the past years, more and more services offer two-factor authentication for their users. Having factors out of two of the three categories something you know, something you have and something…

密码学与安全 · 计算机科学 2022-07-07 Timon Hackenjos , Benedikt Wagner , Julian Herr , Jochen Rill , Marek Wehmer , Niklas Goerke , Ingmar Baumgart

The adoption of FIDO2 authentication by major tech companies in web applications has grown significantly in recent years. However, we argue FIDO2 has broader potential applications. In this paper, we introduce EAP-FIDO, a novel Extensible…

密码学与安全 · 计算机科学 2025-05-19 Martiño Rivera-Dourado , Christos Xenakis , Alejandro Pazos , Jose Vázquez-Naya

The FIDO2 protocol aims to strengthen or replace password authentication using public-key cryptography. FIDO2 has primarily focused on defending against attacks from afar by remote attackers that compromise a password or attempt to phish…

密码学与安全 · 计算机科学 2023-08-08 Tarun Kumar Yadav , Kent Seamons

FIDO2 and the WebAuthn standard offer phishing-resistant, public-key based authentication but traditionally rely on device-bound cryptographic keys that are not naturally portable across user devices. Recent passkey deployments address this…

密码学与安全 · 计算机科学 2026-01-13 Kemal Bicakci , Fatih Mehmet Varli , Muhammet Emir Korkmaz , Yusuf Uzunay

Forced by regulations and industry demand, banks worldwide are working to open their customers' online banking accounts to third-party services via web-based APIs. By using these so-called Open Banking APIs, third-party companies, such as…

密码学与安全 · 计算机科学 2019-02-01 Daniel Fett , Pedram Hosseyni , Ralf Kuesters

Fast Identity Online 2 (FIDO2), a modern authentication protocol, is gaining popularity as a default strong authentication mechanism. It has been recognized as a leading candidate to overcome limitations (e.g., it is phishing resistant) of…

密码学与安全 · 计算机科学 2023-09-14 Michal Kepkowski , Maciej Machulak , Ian Wood , Dali Kaafar

Single Sign-On (SSO) systems simplify login procedures by using an an Identity Provider (IdP) to issue authentication tokens which can be consumed by Service Providers (SPs). Traditionally, IdPs are modeled as trusted third parties. This is…

密码学与安全 · 计算机科学 2014-12-05 Christian Mainka , Vladislav Mladenov , Jörg Schwenk

OAuth is the new de facto standard for delegating authorization in the web. An important limitation of OAuth is the fact that it was designed for authorization and not for authentication. The usage of OAuth for authentication thus leads to…

密码学与安全 · 计算机科学 2016-01-08 Vladislav Mladenov , Christian Mainka , Jörg Schwenk

BrowserID is a complex, real-world Single Sign-On (SSO) System for web applications recently developed by Mozilla. It employs new HTML5 features (such as web messaging and web storage) and cryptographic assertions to provide decentralized…

密码学与安全 · 计算机科学 2019-01-31 Daniel Fett , Ralf Kuesters , Guido Schmitz

Phishing attacks remain one of the most prevalent threats to online security, with the Anti-Phishing Working Group reporting over 890,000 attacks in Q3 2025 alone. Traditional password-based authentication is particularly vulnerable to such…

密码学与安全 · 计算机科学 2026-04-23 Alexander Berladskyy , Andreas Aßmuth

Unequivocally, a single man in possession of a strong password is not enough to solve the issue of security. Studies indicate that passwords have been subjected to various attacks, regardless of the applied protection mechanisms due to the…

密码学与安全 · 计算机科学 2021-07-02 Anna Angelogianni , Ilias Politis , Christos Xenakis

To protect users from data breaches and phishing attacks, service providers typically implement two-factor authentication (2FA) to add an extra layer of security against suspicious login attempts. However, since 2FA can sometimes hinder…

密码学与安全 · 计算机科学 2024-11-19 Zhi Wang , Xin Yang , Du Chen , Han Gao , Meiqi Tian , Yan Jia , Wanpeng Li

Nowadays, cyberattacks are growing exponentially, causing havoc to Internet users. In particular, authentication attacks constitute the major attack vector where intruders impersonate legitimate users to maliciously access systems or…

密码学与安全 · 计算机科学 2025-06-18 Ang Kok Wee , Eyasu Getahun Chekole , Jianying Zhou

The OAuth 2.0 protocol is one of the most widely deployed authorization/single sign-on (SSO) protocols and also serves as the foundation for the new SSO standard OpenID Connect. Despite the popularity of OAuth, so far analysis efforts were…

密码学与安全 · 计算机科学 2019-01-31 Daniel Fett , Ralf Kuesters , Guido Schmitz

Credential stuffing attacks use stolen passwords to log into victim accounts. To defend against these attacks, recently deployed compromised credential checking (C3) services provide APIs that help users and companies check whether a…

As a case study in cryptographic binding, we present a formal-methods analysis of the cryptographic channel binding mechanisms in the Fast IDentity Online (FIDO) Universal Authentication Framework (UAF) authentication protocol, which seeks…

密码学与安全 · 计算机科学 2025-11-11 Enis Golaszewski , Alan T. Sherman , Edward Zieglar , Jonathan D. Fuchs , Sophia Hamer

Today, two-factor authentication (2FA) is a widely implemented mechanism to counter phishing attacks. Although much effort has been investigated in 2FA, most 2FA systems are still vulnerable to carefully designed phishing attacks, and some…

密码学与安全 · 计算机科学 2021-09-02 Yuanyi Sun , Sencun Zhu , Yao Zhao , Pengfei Sun
‹ 上一页 1 2 3 10 下一页 ›