Understanding Failures in Security Proofs of Multi-Factor Authentication for Mobile Devices

计算机科学 随机预言 计算机安全 可证明的安全性 数学证明 认证(法律) 身份验证协议 质询-响应身份验证 形式证明 多因素身份验证 密码学 加密 公钥密码术 几何学 数学
作者
Qingxuan Wang,Ding Wang
出处
期刊:IEEE Transactions on Information Forensics and Security [Institute of Electrical and Electronics Engineers]
卷期号:18: 597-612 被引量:22
标识
DOI:10.1109/tifs.2022.3227753
摘要

Multi-factor authentication is a promising way to enhance the security of password-based authenticated key exchange (PAKE) schemes. It is widely deployed in various daily applications for mobile devices (e.g., e-Bank, smart home, and cloud services) to provide the first line of defense for system security. However, despite intensive research, how to design a secure and efficient multi-factor authentication scheme is still a challenging problem. Hundreds of new schemes have been successfully proposed, and many are even equipped with a formal security proof. However, most of them have been shortly found to be insecure and cannot achieve the claimed security goals. Now a paradox arises: How can a multi-factor scheme that was “formally proven secure” later be found insecure? To answer this seemingly contradicting question, this paper takes a substantial first step towards systematically exploring the security proof failures in multi-factor authentication schemes for mobile devices. We first investigate the root causes of the “provable security” failure in vulnerable multi-factor authentication schemes under the random oracle model, and classify them into eight different types in terms of the five steps of conducting a formal security proof. Then, we elaborate on each type of these eight proof failures by examining three typical vulnerable protocols, and suggest corresponding countermeasures. Finally, we conduct a large-scale comparative measurement of 70 representative multi-factor authentication schemes under our extended evaluation criteria. The schemes we select range from 2009 to 2022, and the comparison results suggest that understanding failures in formal security proofs is helpful to design more secure multi-factor authentication protocols for mobile devices.
最长约 10秒,即可获得该文献文件

科研通智能强力驱动
Strongly Powered by AbleSci AI
更新
大幅提高文件上传限制,最高150M (2024-4-1)

科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
Bellis完成签到 ,获得积分10
刚刚
lyyyy发布了新的文献求助10
1秒前
lyyyy完成签到,获得积分20
9秒前
科研通AI2S应助kkk采纳,获得10
11秒前
lint完成签到 ,获得积分10
11秒前
Jason完成签到 ,获得积分10
12秒前
柴胡完成签到,获得积分10
12秒前
13秒前
Apricity发布了新的文献求助10
14秒前
15秒前
科目三应助学霸宇大王采纳,获得10
16秒前
狮子卷卷完成签到,获得积分10
18秒前
安生发布了新的文献求助10
22秒前
23秒前
nini完成签到,获得积分10
24秒前
鸿鹄在天涯完成签到 ,获得积分10
26秒前
今后应助白华苍松采纳,获得10
27秒前
en关闭了en文献求助
27秒前
漂亮电脑发布了新的文献求助10
28秒前
星星发布了新的文献求助10
28秒前
852应助jiaqitang采纳,获得10
28秒前
Jack80应助乐乐乐乐乐乐采纳,获得200
30秒前
31秒前
萧水白应助余凉采纳,获得10
31秒前
研量完成签到 ,获得积分10
32秒前
大娱乐家发布了新的文献求助10
35秒前
Will完成签到,获得积分10
36秒前
SciGPT应助华鹰采纳,获得10
38秒前
40秒前
骨化醇完成签到,获得积分10
41秒前
大娱乐家完成签到,获得积分10
43秒前
可爱的函函应助俏皮诺言采纳,获得10
44秒前
hucanming发布了新的文献求助30
44秒前
不安青牛应助lint采纳,获得10
50秒前
50秒前
52秒前
汉堡包应助Allen采纳,获得10
54秒前
chloe发布了新的文献求助10
54秒前
雪烟飞扬发布了新的文献求助10
56秒前
漂亮电脑完成签到,获得积分20
59秒前
高分求助中
Solution Manual for Strategic Compensation A Human Resource Management Approach 1200
Natural History of Mantodea 螳螂的自然史 1000
Glucuronolactone Market Outlook Report: Industry Size, Competition, Trends and Growth Opportunities by Region, YoY Forecasts from 2024 to 2031 800
A Photographic Guide to Mantis of China 常见螳螂野外识别手册 800
Zeitschrift für Orient-Archäologie 500
Autoregulatory progressive resistance exercise: linear versus a velocity-based flexible model 500
Synchrotron X-Ray Methods in Clay Science 300
热门求助领域 (近24小时)
化学 医学 生物 材料科学 工程类 有机化学 生物化学 物理 内科学 纳米技术 计算机科学 化学工程 复合材料 基因 遗传学 物理化学 催化作用 细胞生物学 免疫学 冶金
热门帖子
关注 科研通微信公众号,转发送积分 3340648
求助须知:如何正确求助?哪些是违规求助? 2968587
关于积分的说明 8634210
捐赠科研通 2648088
什么是DOI,文献DOI怎么找? 1450009
科研通“疑难数据库(出版商)”最低求助积分说明 671632
邀请新用户注册赠送积分活动 660693