How Anywhere Computing Just Killed Your Phone-Based Two-Factor Authentication

How Anywhere Computing Just Killed Your Phone-Based Two-Factor Authentication
复制标题

随处计算如何扼杀基于电话的双因素身份验证

DOI:
10.1007/978-3-662-54970-4_24
复制
发表时间:
2016
期刊:
ArXiv
影响因子:
--
通讯作者:
H. Bos
H. Bos
中科院分区:
--
文献类型:
--
作者:
Radhesh Krishnan Konoth;V. V. D. Veen;H. Bos

文献摘要

被引文献

相似文献

智能手机使用的指数级增长,加上移动技术的最新进步,正在导致(移动)应用行为的转变:应用供应商不再将他们的应用限制在单一平台上,而是增加同步选项,允许用户方便地从手机切换到PC,反之亦然,以便访问他们的服务。这种在多个平台间整合应用的过程本质上消除了它们之间的差距。然而,目前基于移动电话的双因素身份验证(2FA)机制严重依赖于这种分离的存在。它们被用于各种领域(如消费者网上银行服务或企业安全远程访问),以防止恶意软件。例如,有了2FA,攻击者就不能再使用基于pc的恶意软件实例化欺诈性银行交易。
Exponential growth in smartphone usage combined with recent advances in mobile technology is causing a shift in (mobile) app behavior: application vendors no longer restrict their apps to a single platform, but rather add synchronization options that allow users to conveniently switch from mobile to PC or vice versa in order to access their services. This process of integrating apps among multiple platforms essentially removes the gap between them. Current, state of the art, mobile phone-based two-factor authentication (2FA) mechanisms, however, heavily rely on the existence of such separation. They are used in a variety of segments (such as consumer online banking services or enterprise secure remote access) to protect against malware. For example, with 2FA in place, attackers should no longer be able to use their PC-based malware to instantiate fraudulent banking transactions.