中文
相关论文

相关论文: Cryptographic Binding Should Not Be Optional: A Fo…

200 篇论文

Web authentication is a critical component of today's Internet and the digital world we interact with. The FIDO2 protocol enables users to leverage common devices to easily authenticate to online services in both mobile and desktop…

密码学与安全 · 计算机科学 2023-06-22 Wei-Zhu Yeoh , Michal Kepkowski , Gunnar Heide , Dali Kaafar , Lucjan Hanzlik

This paper presents a timing attack on the FIDO2 (Fast IDentity Online) authentication protocol that allows attackers to link user accounts stored in vulnerable authenticators, a serious privacy concern. FIDO2 is a new standard specified by…

密码学与安全 · 计算机科学 2022-05-18 Michal Kepkowski , Lucjan Hanzlik , Ian Wood , Mohamed Ali Kaafar

Unequivocally, a single man in possession of a strong password is not enough to solve the issue of security. Studies indicate that passwords have been subjected to various attacks, regardless of the applied protection mechanisms due to the…

密码学与安全 · 计算机科学 2021-07-02 Anna Angelogianni , Ilias Politis , Christos Xenakis

FIDO2 authentication is starting to be applied in numerous web authentication services, aiming to replace passwords and their known vulnerabilities. However, this new authentication method has not been integrated yet with network…

密码学与安全 · 计算机科学 2024-04-29 Martiño Rivera-Dourado , Marcos Gestal , Alejandro Pazos , Jose Vázquez-Naya

Fast Identity Online 2 (FIDO2), a modern authentication protocol, is gaining popularity as a default strong authentication mechanism. It has been recognized as a leading candidate to overcome limitations (e.g., it is phishing resistant) of…

密码学与安全 · 计算机科学 2023-09-14 Michal Kepkowski , Maciej Machulak , Ian Wood , Dali Kaafar

We consider keyless authentication for point-to-point communication in the presence of a myopic adversary. In particular, the adversary has access to a non-causal noisy version of the transmission and may use this knowledge to choose the…

信息论 · 计算机科学 2020-01-23 Allison Beemer , Eric Graves , Joerg Kliewer , Oliver Kosut , Paul Yu

With the rise of attacks on online accounts in the past years, more and more services offer two-factor authentication for their users. Having factors out of two of the three categories something you know, something you have and something…

密码学与安全 · 计算机科学 2022-07-07 Timon Hackenjos , Benedikt Wagner , Julian Herr , Jochen Rill , Marek Wehmer , Niklas Goerke , Ingmar Baumgart

FIDO2 and the WebAuthn standard offer phishing-resistant, public-key based authentication but traditionally rely on device-bound cryptographic keys that are not naturally portable across user devices. Recent passkey deployments address this…

密码学与安全 · 计算机科学 2026-01-13 Kemal Bicakci , Fatih Mehmet Varli , Muhammet Emir Korkmaz , Yusuf Uzunay

Traditional authentication in radio-frequency (RF) systems enable secure data communication within a network through techniques such as digital signatures and hash-based message authentication codes (HMAC), which suffer from key recovery…

密码学与安全 · 计算机科学 2018-06-20 Baibhab Chatterjee , Debayan Das , Shovan Maity , Shreyas Sen

The adoption of FIDO2 authentication by major tech companies in web applications has grown significantly in recent years. However, we argue FIDO2 has broader potential applications. In this paper, we introduce EAP-FIDO, a novel Extensible…

密码学与安全 · 计算机科学 2025-05-19 Martiño Rivera-Dourado , Christos Xenakis , Alejandro Pazos , Jose Vázquez-Naya

Security protocols are often found to be flawed after their deployment. We present an approach that aims at the neutralization or mitigation of the attacks to flawed protocols: it avoids the complete dismissal of the interested protocol and…

密码学与安全 · 计算机科学 2014-05-28 Michele Peroli , Luca Viganò , Matteo Zavatteri

The FIDO2 protocol aims to strengthen or replace password authentication using public-key cryptography. FIDO2 has primarily focused on defending against attacks from afar by remote attackers that compromise a password or attempt to phish…

密码学与安全 · 计算机科学 2023-08-08 Tarun Kumar Yadav , Kent Seamons

OAuth 2.0 is a popular authorization framework that allows third-party clients such as websites and mobile apps to request limited access to a user's account on another application. The specification classifies clients into different types…

密码学与安全 · 计算机科学 2023-08-03 Jaimandeep Singh , Naveen Kumar Chaudhary

The advancement of low-altitude intelligent networks enables unmanned aerial vehicle (UAV) interconnection via flying ad-hoc networks (FANETs), offering flexibility and decentralized coordination. However, resource constraints, dynamic…

密码学与安全 · 计算机科学 2025-09-23 Yao Wu , Ziye Jia , Qihui Wu , Yian Zhu

Constrained IoT devices are becoming ubiquitous in society and there is a need for secure communication protocols that respect the constraints under which these devices operate. EDHOC is an authenticated key establishment protocol for…

密码学与安全 · 计算机科学 2021-07-16 Karl Norrman , Vaishnavi Sundararajan , Alessandro Bruni

Classical symbolic protocol verification under Dolev--Yao uses binary attacker knowledge (known/unknown). This abstraction misses cumulative side-channel settings, where repeated noisy observations progressively improve attacker knowledge.…

密码学与安全 · 计算机科学 2026-04-28 Murat Moran

Authentication is a fundamental building block of secure quantum networks, essential for quantum cryptographic protocols and often debated as a key limitation of quantum key distribution (QKD) in security standards. Most quantum-safe…

量子物理 · 物理学 2026-02-25 Suchetana Goswami , Mina Doosti , Elham Kashefi

This document presents the security protocol verifier CryptoVerif.CryptoVerif does not rely on the symbolic, Dolev-Yao model, but on the computational model. It can verify secrecy, correspondence (which include authentication), and…

密码学与安全 · 计算机科学 2023-10-24 Bruno Blanchet

The Internet of Drones (IoD) is an emerging and crucial paradigm enabling advanced applications that require seamless, secure communication across heterogeneous and untrusted domains. In such environments, access control and the…

密码学与安全 · 计算机科学 2025-12-29 Xuanyu Chen , Yue Zheng , Junqing Zhang , Guanxiong Shen , Chip-Hong Chang

In most PUF-based authentication schemes, a central server is usually engaged to verify the response of the device's PUF to challenge bit-streams. However, the server availability may be intermittent in practice. To tackle such an issue,…

密码学与安全 · 计算机科学 2022-06-15 Mohammad Ebrahimabadi , Mohamed Younis , Wassila Lalouani , Naghmeh Karimi
‹ 上一页 1 2 3 10 下一页 ›