How Anywhere Computing Just Killed Your Phone-Based Two-Factor Authentication
How Anywhere Computing Just Killed Your Phone-Based Two-Factor Authentication
复制标题
随处计算如何扼杀基于电话的双因素身份验证
DOI:
10.1007/978-3-662-54970-4_24
复制
发表时间:
2016
期刊:
影响因子:
--
通讯作者:
H. Bos
中科院分区:
文献类型:
--
作者:
Radhesh Krishnan Konoth;V. V. D. Veen;H. Bos
Exponential growth in smartphone usage combined with recent advances in mobile technology is causing a shift in (mobile) app behavior: application vendors no longer restrict their apps to a single platform, but rather add synchronization options that allow users to conveniently switch from mobile to PC or vice versa in order to access their services. This process of integrating apps among multiple platforms essentially removes the gap between them. Current, state of the art, mobile phone-based two-factor authentication (2FA) mechanisms, however, heavily rely on the existence of such separation. They are used in a variety of segments (such as consumer online banking services or enterprise secure remote access) to protect against malware. For example, with 2FA in place, attackers should no longer be able to use their PC-based malware to instantiate fraudulent banking transactions.