CICI: UCSS: Towards Secure and Usable Push Notification Authentication for Collaborative Scientific Infrastructures
CICI: UCSS: Towards Secure and Usable Push Notification Authentication for Collaborative Scientific Infrastructures
批准号:
2115107
负责人:
Nitesh Saxena
金额:
$49.99万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2021
资助国家:
美国
项目状态:
已结题
起止时间:
2021-08-15 至 2021-09-30
中文摘要
第二因素(2FA)或无密码认证基于通知推送到用户的个人设备(例如,一个电话),用户可以简单地批准(或拒绝)已经变得广泛流行,因为它的便利性,特别是保护科学资源在大学和类似的组织。该项目研究的前提是,这种方法的轻松性会导致并发登录会话(一个由用户发起,另一个由攻击者发起)引起的基本设计漏洞,然后重新设计基于推送的身份验证系统,可以在不降低该方法整体可用性的情况下对抗已识别的漏洞。提出的新设计试图通过在用户的浏览器会话和推送通知之间建立唯一的绑定来解决并发登录攻击。该研究包括三个相互关联的活动:(1)形式化和研究针对标准推送通知认证方案的基本漏洞;(2)设计和实现低工作量的基于推送的认证方案,在不影响可用性的情况下击败已识别的漏洞;(3)在实验室环境和现场环境中对提出的新的基于推送的认证方案进行正式研究。开发的弹性推送认证系统设计预计将为科学和协作环境中的日常用户提供更高水平的保护、可访问性和可用性。研究原型有望在未来构建弹性和可用的认证服务的实践研究中具有更广泛的价值。该项目通过与基于推送的身份验证领域的主要参与者合作来强调技术转让。拟议的研究正在以高级课程发展和在认证和人机交互等广泛领域的学生指导的形式与教育活动结合起来,高中和K-12学生和少数民族人口的参与正在扩大项目的范围。该奖项反映了美国国家科学基金会的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Second factor (2FA) or passwordless authentication based on notifications pushed to a user's personal device (e.g., a phone) that the user can simply approve (or deny) has become widely popular due to its convenience, especially to protect scientific resources at Universities and similar organizations. This project is studying the premise that the effortlessness of this approach gives rise to a fundamental design vulnerability arising from concurrent login sessions (one initiated by the user and the other initiated by the attacker), and then redesigning push-based authentication systems that can counter the identified vulnerability without degrading the overall usability of the approach. The proposed new design attempts to address the concurrent login attacks by establishing a unique binding between the user’s browser session and the push notification.The research consists of three inter-related activities: (1) formalization and study of a fundamental vulnerability against standard push notification authentication schemes; (2) design and implementation of low-effort push-based authentication schemes that can defeat the identified vulnerability without undermining the usability; and (3) formal studies of the proposed new push-based authentication schemes, conducted in lab settings and field environments. The developed resilient push authentication system designs are expected to offer an improved level of protection, accessibility and usability to everyday users in scientific and collaborative settings. The research prototypes are expected to be of broader value in future research on building resilient and usable authentication services in practice. The project is emphasizing technology transfer by working with major players in the push-based authentication domain. The proposed research is being integrated with educational activities in the form of advanced curriculum development and student mentoring in the broad domains of Authentication and Human-Computer Interaction, and the involvement of high school and K-12 students and minority populations are broadening the reach of the project.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Collaborative Research: SaTC: CORE: Medium: Bubble Aid: Assistive AI to Improve the Robustness and Security of Reading Hand-Marked Ballots
-
批准号:2154507
-
项目类别:Continuing Grant
-
资助金额:$39.96万
-
财政年份:2022
-
负责人:Nitesh Saxena
-
依托单位:
CICI: UCSS: Towards Secure and Usable Push Notification Authentication for Collaborative Scientific Infrastructures
-
批准号:2139358
-
项目类别:Standard Grant
-
资助金额:$49.99万
-
财政年份:2021
-
负责人:Nitesh Saxena
-
依托单位:
Collaborative Research: SaTC: TTP: Medium: Intrusion-Tolerant Outsourced Storage for Cyber-Infrastructure
-
批准号:2201465
-
项目类别:Standard Grant
-
资助金额:$58.5万
-
财政年份:2021
-
负责人:Nitesh Saxena
-
依托单位:
SaTC: TTP: Small: SPHINX: A Password Store that Perfectly Hides Passwords from Itself
-
批准号:2152669
-
项目类别:Standard Grant
-
资助金额:$45.0万
-
财政年份:2021
-
负责人:Nitesh Saxena
-
依托单位:
Collaborative Research: SaTC: TTP: Medium: Intrusion-Tolerant Outsourced Storage for Cyber-Infrastructure
-
批准号:2030501
-
项目类别:Standard Grant
-
资助金额:$58.5万
-
财政年份:2020
-
负责人:Nitesh Saxena
-
依托单位:
SaTC: TTP: Small: SPHINX: A Password Store that Perfectly Hides Passwords from Itself
-
批准号:1714807
-
项目类别:Standard Grant
-
资助金额:$45.0万
-
财政年份:2017
-
负责人:Nitesh Saxena
-
依托单位:
CICI: Secure Data Architecture: Improving the Security and Usability of Two-Factor Authentication for Cyberinfrastructure
-
批准号:1547350
-
项目类别:Standard Grant
-
资助金额:$24.97万
-
财政年份:2016
-
负责人:Nitesh Saxena
-
依托单位:
TWC: Small: Collaborative: Spoof-Resistant Smartphone Authentication using Cooperating Wearables
-
批准号:1526524
-
项目类别:Standard Grant
-
资助金额:$20.8万
-
财政年份:2015
-
负责人:Nitesh Saxena
-
依托单位:
EAGER: Establishing Secure Wireless Connections via Playful User Engagement
-
批准号:1255919
-
项目类别:Standard Grant
-
资助金额:$7.5万
-
财政年份:2012
-
负责人:Nitesh Saxena
-
依托单位:
CT-ISG: User-Aided Secure Association of Wireless Devices
-
批准号:1228236
-
项目类别:Standard Grant
-
资助金额:$5.92万
-
财政年份:2012
-
负责人:Nitesh Saxena
-
依托单位:
TC: Small: Mobile Phone Password Managers: An Evaluation and a Re-Design based on Human-Perceptible Communication
-
批准号:1117269
-
项目类别:Standard Grant
-
资助金额:$45.34万
-
财政年份:2011
-
负责人:Nitesh Saxena
-
依托单位:
EAGER: Collaborative Research: Towards Context-Aware Security and Privacy for RFID Systems
-
批准号:1153650
-
项目类别:Standard Grant
-
资助金额:$9.0万
-
财政年份:2011
-
负责人:Nitesh Saxena
-
依托单位:
EAGER: Collaborative Research: Towards Context-Aware Security and Privacy for RFID Systems
-
批准号:1201927
-
项目类别:Standard Grant
-
资助金额:$9.0万
-
财政年份:2011
-
负责人:Nitesh Saxena
-
依托单位:
TC: Small: Mobile Phone Password Managers: An Evaluation and a Re-Design based on Human-Perceptible Communication
-
批准号:1209280
-
项目类别:Standard Grant
-
资助金额:$45.34万
-
财政年份:2011
-
负责人:Nitesh Saxena
-
依托单位:
CT-ISG: User-Aided Secure Association of Wireless Devices
-
批准号:0831397
-
项目类别:Standard Grant
-
资助金额:$0.0万
-
财政年份:2008
-
负责人:Nitesh Saxena
-
依托单位:
海外基金