CICI: UCSS: Towards Secure and Usable Push Notification Authentication for Collaborative Scientific Infrastructures
CICI:UCSS:为协作科学基础设施实现安全可用的推送通知身份验证
基本信息
- 批准号:2115107
- 负责人:
- 金额:$ 49.99万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Standard Grant
- 财政年份:2021
- 资助国家:美国
- 起止时间:2021-08-15 至 2021-09-30
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
Second factor (2FA) or passwordless authentication based on notifications pushed to a user's personal device (e.g., a phone) that the user can simply approve (or deny) has become widely popular due to its convenience, especially to protect scientific resources at Universities and similar organizations. This project is studying the premise that the effortlessness of this approach gives rise to a fundamental design vulnerability arising from concurrent login sessions (one initiated by the user and the other initiated by the attacker), and then redesigning push-based authentication systems that can counter the identified vulnerability without degrading the overall usability of the approach. The proposed new design attempts to address the concurrent login attacks by establishing a unique binding between the user’s browser session and the push notification.The research consists of three inter-related activities: (1) formalization and study of a fundamental vulnerability against standard push notification authentication schemes; (2) design and implementation of low-effort push-based authentication schemes that can defeat the identified vulnerability without undermining the usability; and (3) formal studies of the proposed new push-based authentication schemes, conducted in lab settings and field environments. The developed resilient push authentication system designs are expected to offer an improved level of protection, accessibility and usability to everyday users in scientific and collaborative settings. The research prototypes are expected to be of broader value in future research on building resilient and usable authentication services in practice. The project is emphasizing technology transfer by working with major players in the push-based authentication domain. The proposed research is being integrated with educational activities in the form of advanced curriculum development and student mentoring in the broad domains of Authentication and Human-Computer Interaction, and the involvement of high school and K-12 students and minority populations are broadening the reach of the project.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
第二因素(2FA)或基于推送到用户个人设备的通知的无密码认证(例如,电话),用户可以简单地批准(或拒绝),由于其便利性,特别是为了保护大学和类似组织的科学资源,已经变得广泛流行。该项目正在研究的前提是,这种方法的轻松性会导致并发登录会话(一个由用户发起,另一个由攻击者发起)引起的基本设计漏洞,然后重新设计基于推送的身份验证系统,可以对抗已识别的漏洞,而不会降低该方法的整体可用性。本文提出的新设计试图通过在用户浏览器会话和推送通知之间建立一个唯一的绑定来解决并发登录攻击,研究包括三个相互关联的活动:(1)针对标准推送通知认证方案的基本漏洞的形式化和研究;(2)设计和实现低工作量的基于推送的认证方案,该方案可以在不破坏可用性的情况下击败所识别的漏洞;以及(3)在实验室设置和现场环境中对所提出的新的基于推送的认证方案进行正式研究。预计开发的弹性推送认证系统设计将为科学和协作环境中的日常用户提供更高级别的保护,可访问性和可用性。研究原型预计将在未来的研究更广泛的价值在实践中建立弹性和可用的认证服务。该项目通过与基于推送的认证领域的主要参与者合作,强调技术转让。拟议中的研究正在与教育活动相结合,以先进的课程开发和学生指导的形式,在认证和人机交互的广泛领域,以及高中和K-这个奖项反映了NSF的法定使命,并通过使用基金会的知识产权进行评估,被认为值得支持。优点和更广泛的影响审查标准。
项目成果
期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
数据更新时间:{{ journalArticles.updateTime }}
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Nitesh Saxena其他文献
PASSAT: Single Password Authenticated Secret-Shared Intrusion-Tolerant Storage with Server Transparency
PASSAT:具有服务器透明性的单密码验证秘密共享入侵容忍存储
- DOI:
- 发表时间:
2021 - 期刊:
- 影响因子:0
- 作者:
Kiavash Satvat;Maliheh Shirvanian;Nitesh Saxena - 通讯作者:
Nitesh Saxena
Public Key Cryptography Sans Certificates in Ad Hoc Networks
Ad Hoc 网络中的公钥加密无证书
- DOI:
10.1007/11767480_26 - 发表时间:
2006 - 期刊:
- 影响因子:0
- 作者:
Nitesh Saxena - 通讯作者:
Nitesh Saxena
Gene Regulation and Species-Specific Evolution of Free Flight Odor Tracking in Drosophila
果蝇自由飞行气味追踪的基因调控和物种特异性进化
- DOI:
10.1093/molbev/msx241 - 发表时间:
2018 - 期刊:
- 影响因子:10.7
- 作者:
B. Houot;Laurie Cazalé;S. Fraichard;C. Everaerts;Nitesh Saxena;S. Sane;J. Ferveur - 通讯作者:
J. Ferveur
Robust self-keying mobile ad hoc networks
强大的自键控移动自组织网络
- DOI:
10.1016/j.comnet.2006.07.009 - 发表时间:
2007 - 期刊:
- 影响因子:0
- 作者:
C. Castelluccia;Nitesh Saxena;J. Yi - 通讯作者:
J. Yi
Towards Sensing-Enabled RFID Security and Privacy
迈向传感型 RFID 安全和隐私
- DOI:
10.4018/978-1-4666-1990-6.ch003 - 发表时间:
2013 - 期刊:
- 影响因子:0
- 作者:
Di Ma;Nitesh Saxena - 通讯作者:
Nitesh Saxena
Nitesh Saxena的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Nitesh Saxena', 18)}}的其他基金
Collaborative Research: SaTC: CORE: Medium: Bubble Aid: Assistive AI to Improve the Robustness and Security of Reading Hand-Marked Ballots
合作研究:SaTC:核心:媒介:Bubble Aid:辅助人工智能提高阅读手写选票的稳健性和安全性
- 批准号:
2154507 - 财政年份:2022
- 资助金额:
$ 49.99万 - 项目类别:
Continuing Grant
CICI: UCSS: Towards Secure and Usable Push Notification Authentication for Collaborative Scientific Infrastructures
CICI:UCSS:为协作科学基础设施实现安全可用的推送通知身份验证
- 批准号:
2139358 - 财政年份:2021
- 资助金额:
$ 49.99万 - 项目类别:
Standard Grant
Collaborative Research: SaTC: TTP: Medium: Intrusion-Tolerant Outsourced Storage for Cyber-Infrastructure
协作研究:SaTC:TTP:中:网络基础设施的耐入侵外包存储
- 批准号:
2201465 - 财政年份:2021
- 资助金额:
$ 49.99万 - 项目类别:
Standard Grant
SaTC: TTP: Small: SPHINX: A Password Store that Perfectly Hides Passwords from Itself
SaTC:TTP:小型:SPHINX:完美隐藏密码的密码存储
- 批准号:
2152669 - 财政年份:2021
- 资助金额:
$ 49.99万 - 项目类别:
Standard Grant
Collaborative Research: SaTC: TTP: Medium: Intrusion-Tolerant Outsourced Storage for Cyber-Infrastructure
协作研究:SaTC:TTP:中:网络基础设施的耐入侵外包存储
- 批准号:
2030501 - 财政年份:2020
- 资助金额:
$ 49.99万 - 项目类别:
Standard Grant
SaTC: TTP: Small: SPHINX: A Password Store that Perfectly Hides Passwords from Itself
SaTC:TTP:小型:SPHINX:完美隐藏密码的密码存储
- 批准号:
1714807 - 财政年份:2017
- 资助金额:
$ 49.99万 - 项目类别:
Standard Grant
CICI: Secure Data Architecture: Improving the Security and Usability of Two-Factor Authentication for Cyberinfrastructure
CICI:安全数据架构:提高网络基础设施双因素身份验证的安全性和可用性
- 批准号:
1547350 - 财政年份:2016
- 资助金额:
$ 49.99万 - 项目类别:
Standard Grant
TWC: Small: Collaborative: Spoof-Resistant Smartphone Authentication using Cooperating Wearables
TWC:小型:协作:使用协作可穿戴设备进行防欺骗智能手机身份验证
- 批准号:
1526524 - 财政年份:2015
- 资助金额:
$ 49.99万 - 项目类别:
Standard Grant
EAGER: Establishing Secure Wireless Connections via Playful User Engagement
EAGER:通过有趣的用户参与建立安全的无线连接
- 批准号:
1255919 - 财政年份:2012
- 资助金额:
$ 49.99万 - 项目类别:
Standard Grant
CT-ISG: User-Aided Secure Association of Wireless Devices
CT-ISG:用户辅助的无线设备安全关联
- 批准号:
1228236 - 财政年份:2012
- 资助金额:
$ 49.99万 - 项目类别:
Standard Grant
相似海外基金
CICI: UCSS: Human-Centered Cybersecurity in Robotic Surgery (HCCRS) - Coordinating the Human and Cyber Infrastructure for Cybersecurity
CICI:UCCSS:机器人手术中以人为中心的网络安全 (HCCCS) - 协调网络安全的人力和网络基础设施
- 批准号:
2319891 - 财政年份:2023
- 资助金额:
$ 49.99万 - 项目类别:
Standard Grant
CICI: UCSS: Trusted Resource Allocation in Volunteer Edge-Cloud Computing Workflows
CICI:UCSS:志愿者边缘云计算工作流程中的可信资源分配
- 批准号:
2232889 - 财政年份:2023
- 资助金额:
$ 49.99万 - 项目类别:
Standard Grant
CICI: UCSS: Building a Community of Practice for Supporting Regulated Research
CICI:UCSS:建立支持监管研究的实践社区
- 批准号:
2409859 - 财政年份:2023
- 资助金额:
$ 49.99万 - 项目类别:
Standard Grant
CICI: UCSS: Enhancing the Usability of Vulnerability Assessment Results for Open-Source Software Technologies in Scientific Cyberinfrastructure: A Deep Learning Perspective
CICI:UCSS:增强科学网络基础设施中开源软件技术漏洞评估结果的可用性:深度学习视角
- 批准号:
2319325 - 财政年份:2023
- 资助金额:
$ 49.99万 - 项目类别:
Standard Grant
CICI: UCSS: Secure Containers in High-Performance Computing Infrastructure
CICI:UCSS:高性能计算基础设施中的安全容器
- 批准号:
2319975 - 财政年份:2023
- 资助金额:
$ 49.99万 - 项目类别:
Standard Grant
CICI: UCSS: Maximizing Data Utility and Participant Privacy through Usable, Secure Data Workflows for Human-Centered AI Research
CICI:UCSS:通过可用、安全的数据工作流程实现以人为本的人工智能研究,最大限度地提高数据效用和参与者隐私
- 批准号:
2232690 - 财政年份:2023
- 资助金额:
$ 49.99万 - 项目类别:
Standard Grant
CICI: UCSS: Confidential Computing in Reproducible Collaborative Workflows
CICI:UCSS:可重复协作工作流程中的机密计算
- 批准号:
2232824 - 财政年份:2023
- 资助金额:
$ 49.99万 - 项目类别:
Standard Grant
CICI: UCSS: ScienceAccess: Enabling Zero-Trust Resource Access Management for Scientific Collaborations
CICI:UCSS:ScienceAccess:为科学合作实现零信任资源访问管理
- 批准号:
2232911 - 财政年份:2022
- 资助金额:
$ 49.99万 - 项目类别:
Standard Grant
CICI: UCSS: Building a Community of Practice for Supporting Regulated Research
CICI:UCSS:建立支持监管研究的实践社区
- 批准号:
2201028 - 财政年份:2021
- 资助金额:
$ 49.99万 - 项目类别:
Standard Grant
CICI: UCSS: SciAuth: Deploying Interoperable and Usable Authorization Tokens to Enable Scientific Collaborations
CICI:UCSS:SciAuth:部署可互操作和可用的授权令牌以实现科学协作
- 批准号:
2114989 - 财政年份:2021
- 资助金额:
$ 49.99万 - 项目类别:
Standard Grant