MPKIX: Towards More Accountable and Secure Internet Application Services via Mobile Networked Systems

MPKIX: Towards More Accountable and Secure Internet Application Services via Mobile Networked Systems
复制标题

DOI:
10.1109/tmc.2022.3141694
复制
发表时间:
2023-06
影响因子:
7.9
通讯作者:
Tian Xie;Sihan Wang;Xinyu Lei;Jingwen Shi;Guan-Hua Tu;Chi-Yu Li
Tian Xie;Sihan Wang;Xinyu Lei;Jingwen Shi;Guan-Hua Tu;Chi-Yu Li
中科院分区:
计算机科学2区
文献类型:
--
作者:
Tian Xie;Sihan Wang;Xinyu Lei;Jingwen Shi;Guan-Hua Tu;Chi-Yu Li

文献摘要

相似文献

目前,互联网应用服务(IAS)提供商和用户都面临着各种安全威胁和法律的问题。由于缺乏可靠的用户信息验证机制,攻击者可以通过使用虚假用户帐户来滥用IAS发起各种网络攻击,例如分发错误信息和网络钓鱼。因此,IAS提供商可能会无意中向受限用户提供不适当的内容,从而面临根据当地或国际法律被起诉的严重风险。此外,IAS用户可能会遭受恶意的ID盗窃攻击。在本文中,我们提出了一种新的安全框架,${{\sf MPKIX}}$MPKIX,指定为移动辅助的公钥基础设施X. 509(公钥基础设施X. 509)。${{\sf MPKIX}}$MPKIX通过利用广泛使用的PKIX服务和移动的联网系统来保护IAS提供商和用户。它不仅为IAS提供商提供了可靠的用户验证机制,同时实现了跨IAS用户隐私保护,而且大大降低了ID盗窃攻击的可能性,并使其他相关方受益,例如蜂窝网络运营商和PKIX服务提供商。我们进一步对${{\sf MPKIX}}$MPKIX进行了安全性分析,并实现了${{\sf MPKIX}}$MPKIX原型。基于原型的评估结果证实了${{\sf MPKIX}}$MPKIX的有效性和效率,具有较低的开销。
Nowadays, both Internet Application Service (IAS) providers and users face various security threats and legal issues. Due to the lack of reliable user information verification mechanisms, adversaries can abuse IASs to launch various cyberattacks, such as misinformation distributing and phishing, by using fake user accounts. IAS providers may thus inadvertently offer inappropriate content to restricted users, thereby suffering a serious risk of prosecution under local or international laws. Also, IAS users may suffer from nefarious ID theft attacks. In this paper, we proposed a novel security framework, ${{\sf MPKIX}}$MPKIX, designated as Mobile-assisted PKIX (Public-Key Infrastructure X.509). ${{\sf MPKIX}}$MPKIX secures both IAS providers and users by leveraging the broadly used PKIX services and mobile networked systems. It not only provides IAS providers with a reliable user verification mechanism while simultaneously enabling cross-IAS user privacy protection, but also largely mitigates the possibility of ID theft attacks and benefits other involved parties, such as cellular network operators and PKIX service providers. We further conduct a security analysis of ${{\sf MPKIX}}$MPKIX and implement an ${{\sf MPKIX}}$MPKIX prototype. The evaluation results based on the prototype confirm the effectiveness and efficiency of ${{\sf MPKIX}}$MPKIX with low overhead.