CICI: UCSS: Towards Secure and Usable Push Notification Authentication for Collaborative Scientific Infrastructures
CICI: UCSS: Towards Secure and Usable Push Notification Authentication for Collaborative Scientific Infrastructures
批准号:
2115107
负责人:
Nitesh Saxena
金额:
$49.99万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2021
资助国家:
美国
项目状态:
已结题
起止时间:
2021-08-15 至 2021-09-30
中文摘要
第二个因素(2FA)或基于推送到用户的个人设备(例如,电话)的通知的无密码身份验证由于其便利性而变得广泛流行,尤其是在保护大学和类似组织的科学资源方面。该项目正在研究这样一个前提,即这种方法的毫不费力会导致由并发登录会话(一个由用户发起,另一个由攻击者发起)产生的基本设计漏洞,然后重新设计基于推送的身份验证系统,该系统可以在不降低该方法的整体可用性的情况下应对已识别的漏洞。提出的新设计试图通过在用户的浏览器会话和推送通知之间建立唯一的绑定来应对并发登录攻击,研究包括三个相互关联的活动:(1)针对标准推送通知认证方案的基本漏洞的形式化和研究;(2)设计和实现低工作量的基于推送的认证方案,该方案可以在不破坏可用性的情况下击败已识别的漏洞;(3)在实验室和现场环境中对提出的新的基于推送的认证方案进行正式研究。开发的弹性推送身份验证系统设计预计将在科学和协作环境中为日常用户提供更高水平的保护、可访问性和可用性。这些研究原型有望对未来在实践中构建具有弹性和可用性的认证服务的研究具有更广泛的价值。该项目通过与基于推送的身份验证领域的主要参与者合作,强调技术转让。拟议的研究正在与教育活动相结合,在认证和人机交互的广泛领域以高级课程开发和学生指导的形式,高中和K-12学生以及少数群体的参与扩大了项目的范围。该奖项反映了NSF的法定使命,并通过使用基金会的智力优势和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Second factor (2FA) or passwordless authentication based on notifications pushed to a user's personal device (e.g., a phone) that the user can simply approve (or deny) has become widely popular due to its convenience, especially to protect scientific resources at Universities and similar organizations. This project is studying the premise that the effortlessness of this approach gives rise to a fundamental design vulnerability arising from concurrent login sessions (one initiated by the user and the other initiated by the attacker), and then redesigning push-based authentication systems that can counter the identified vulnerability without degrading the overall usability of the approach. The proposed new design attempts to address the concurrent login attacks by establishing a unique binding between the user’s browser session and the push notification.The research consists of three inter-related activities: (1) formalization and study of a fundamental vulnerability against standard push notification authentication schemes; (2) design and implementation of low-effort push-based authentication schemes that can defeat the identified vulnerability without undermining the usability; and (3) formal studies of the proposed new push-based authentication schemes, conducted in lab settings and field environments. The developed resilient push authentication system designs are expected to offer an improved level of protection, accessibility and usability to everyday users in scientific and collaborative settings. The research prototypes are expected to be of broader value in future research on building resilient and usable authentication services in practice. The project is emphasizing technology transfer by working with major players in the push-based authentication domain. The proposed research is being integrated with educational activities in the form of advanced curriculum development and student mentoring in the broad domains of Authentication and Human-Computer Interaction, and the involvement of high school and K-12 students and minority populations are broadening the reach of the project.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Collaborative Research: SaTC: CORE: Medium: Bubble Aid: Assistive AI to Improve the Robustness and Security of Reading Hand-Marked Ballots
-
批准号:2154507
-
项目类别:Continuing Grant
-
资助金额:$39.96万
-
财政年份:2022
-
负责人:Nitesh Saxena
-
依托单位:
CICI: UCSS: Towards Secure and Usable Push Notification Authentication for Collaborative Scientific Infrastructures
-
批准号:2139358
-
项目类别:Standard Grant
-
资助金额:$49.99万
-
财政年份:2021
-
负责人:Nitesh Saxena
-
依托单位:
Collaborative Research: SaTC: TTP: Medium: Intrusion-Tolerant Outsourced Storage for Cyber-Infrastructure
-
批准号:2201465
-
项目类别:Standard Grant
-
资助金额:$58.5万
-
财政年份:2021
-
负责人:Nitesh Saxena
-
依托单位:
SaTC: TTP: Small: SPHINX: A Password Store that Perfectly Hides Passwords from Itself
-
批准号:2152669
-
项目类别:Standard Grant
-
资助金额:$45.0万
-
财政年份:2021
-
负责人:Nitesh Saxena
-
依托单位:
Collaborative Research: SaTC: TTP: Medium: Intrusion-Tolerant Outsourced Storage for Cyber-Infrastructure
-
批准号:2030501
-
项目类别:Standard Grant
-
资助金额:$58.5万
-
财政年份:2020
-
负责人:Nitesh Saxena
-
依托单位:
SaTC: TTP: Small: SPHINX: A Password Store that Perfectly Hides Passwords from Itself
-
批准号:1714807
-
项目类别:Standard Grant
-
资助金额:$45.0万
-
财政年份:2017
-
负责人:Nitesh Saxena
-
依托单位:
CICI: Secure Data Architecture: Improving the Security and Usability of Two-Factor Authentication for Cyberinfrastructure
-
批准号:1547350
-
项目类别:Standard Grant
-
资助金额:$24.97万
-
财政年份:2016
-
负责人:Nitesh Saxena
-
依托单位:
TWC: Small: Collaborative: Spoof-Resistant Smartphone Authentication using Cooperating Wearables
-
批准号:1526524
-
项目类别:Standard Grant
-
资助金额:$20.8万
-
财政年份:2015
-
负责人:Nitesh Saxena
-
依托单位:
EAGER: Establishing Secure Wireless Connections via Playful User Engagement
-
批准号:1255919
-
项目类别:Standard Grant
-
资助金额:$7.5万
-
财政年份:2012
-
负责人:Nitesh Saxena
-
依托单位:
CT-ISG: User-Aided Secure Association of Wireless Devices
-
批准号:1228236
-
项目类别:Standard Grant
-
资助金额:$5.92万
-
财政年份:2012
-
负责人:Nitesh Saxena
-
依托单位:
TC: Small: Mobile Phone Password Managers: An Evaluation and a Re-Design based on Human-Perceptible Communication
-
批准号:1117269
-
项目类别:Standard Grant
-
资助金额:$45.34万
-
财政年份:2011
-
负责人:Nitesh Saxena
-
依托单位:
EAGER: Collaborative Research: Towards Context-Aware Security and Privacy for RFID Systems
-
批准号:1153650
-
项目类别:Standard Grant
-
资助金额:$9.0万
-
财政年份:2011
-
负责人:Nitesh Saxena
-
依托单位:
EAGER: Collaborative Research: Towards Context-Aware Security and Privacy for RFID Systems
-
批准号:1201927
-
项目类别:Standard Grant
-
资助金额:$9.0万
-
财政年份:2011
-
负责人:Nitesh Saxena
-
依托单位:
TC: Small: Mobile Phone Password Managers: An Evaluation and a Re-Design based on Human-Perceptible Communication
-
批准号:1209280
-
项目类别:Standard Grant
-
资助金额:$45.34万
-
财政年份:2011
-
负责人:Nitesh Saxena
-
依托单位:
CT-ISG: User-Aided Secure Association of Wireless Devices
-
批准号:0831397
-
项目类别:Standard Grant
-
资助金额:$0.0万
-
财政年份:2008
-
负责人:Nitesh Saxena
-
依托单位:
海外基金