Issues of Clinical Identity Verification for Healthcare Applications over Mobile Terminal Platform

Issues of Clinical Identity Verification for Healthcare Applications over Mobile Terminal Platform
复制标题

DOI:
10.1155/2022/6245397
复制
发表时间:
2022-04-19
影响因子:
--
通讯作者:
Kaur, Amandeep
Kaur, Amandeep
中科院分区:
计算机科学4区
文献类型:
--
作者:
Ahmad, Sultan;Abdeljaber, Hikmat A. M.;Kaur, Amandeep

文献摘要

被引文献

相似文献

根据最近的研究,对USIM卡的攻击正在上升。在5G环境中,攻击者还可以使用伪造的USIM卡来绕过指定标准应用程序的身份认证并窃取用户信息。在USIM可复制的假设下,研究了常见移动的平台应用的身份认证过程。身份认证树是通过检查用户登录、密码重置和敏感操作等应用程序行为生成的。我们测试了7个类别的58个典型应用程序,包括社交通信和个人健康。我们发现,其中29人只需要USIM卡收到的短信验证码就可以通过认证。针对这一问题,建议开启两步验证,使用USIM防伪方式完成验证。
According to recent research, attacks on USIM cards are on the rise. In a 5G setting, attackers can also employ counterfeit USIM cards to circumvent the identity authentication of specified standard applications and steal user information. Under the assumption that the USIM can be replicated, the identity authentication process of common mobile platform applications is investigated. The identity authentication tree is generated by examining the application behavior of user login, password reset, and sensitive operations. We tested 58 typical applications in 7 categories, including social communication and personal health. We found that 29 of them only needed the SMS verification code received by the USIM card to pass the authentication. In response to this problem, it is recommended to enable two-step verification and use USIM anti-counterfeiting methods to complete the verification.