Understanding Failures in Security Proofs of Multi-Factor Authentication for Mobile Devices

计算机科学 随机预言 计算机安全 可证明的安全性 数学证明 认证(法律) 身份验证协议 质询-响应身份验证 形式证明 多因素身份验证 密码学 加密 公钥密码术 几何学 数学
作者
Qingxuan Wang,Ding Wang
出处
期刊:IEEE Transactions on Information Forensics and Security [Institute of Electrical and Electronics Engineers]
卷期号:18: 597-612 被引量:22
标识
DOI:10.1109/tifs.2022.3227753
摘要

Multi-factor authentication is a promising way to enhance the security of password-based authenticated key exchange (PAKE) schemes. It is widely deployed in various daily applications for mobile devices (e.g., e-Bank, smart home, and cloud services) to provide the first line of defense for system security. However, despite intensive research, how to design a secure and efficient multi-factor authentication scheme is still a challenging problem. Hundreds of new schemes have been successfully proposed, and many are even equipped with a formal security proof. However, most of them have been shortly found to be insecure and cannot achieve the claimed security goals. Now a paradox arises: How can a multi-factor scheme that was “formally proven secure” later be found insecure? To answer this seemingly contradicting question, this paper takes a substantial first step towards systematically exploring the security proof failures in multi-factor authentication schemes for mobile devices. We first investigate the root causes of the “provable security” failure in vulnerable multi-factor authentication schemes under the random oracle model, and classify them into eight different types in terms of the five steps of conducting a formal security proof. Then, we elaborate on each type of these eight proof failures by examining three typical vulnerable protocols, and suggest corresponding countermeasures. Finally, we conduct a large-scale comparative measurement of 70 representative multi-factor authentication schemes under our extended evaluation criteria. The schemes we select range from 2009 to 2022, and the comparison results suggest that understanding failures in formal security proofs is helpful to design more secure multi-factor authentication protocols for mobile devices.
最长约 10秒,即可获得该文献文件

科研通智能强力驱动
Strongly Powered by AbleSci AI
更新
PDF的下载单位、IP信息已删除 (2025-6-4)

科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
刚刚
材料打工人完成签到 ,获得积分10
刚刚
懦弱的难敌完成签到,获得积分10
1秒前
1秒前
顾矜应助过奖啦采纳,获得10
1秒前
清水巍少发布了新的文献求助10
1秒前
Cissy发布了新的文献求助10
1秒前
luckysame发布了新的文献求助10
2秒前
惜云发布了新的文献求助10
2秒前
冲鸭完成签到,获得积分10
2秒前
赘婿应助yfy采纳,获得10
3秒前
yuyu发布了新的文献求助10
4秒前
4秒前
5秒前
5秒前
所所应助怕热除铁采纳,获得10
6秒前
孤独的涔完成签到,获得积分10
6秒前
jazz完成签到,获得积分10
6秒前
白昼の月完成签到 ,获得积分0
7秒前
鱼鱼鱼发布了新的文献求助10
7秒前
坦率的香烟完成签到,获得积分10
7秒前
7秒前
大方小苏完成签到,获得积分10
8秒前
8秒前
9秒前
自觉紫山发布了新的文献求助10
9秒前
9秒前
10秒前
酷波er应助biubiu采纳,获得10
11秒前
11秒前
三十三完成签到,获得积分10
11秒前
11秒前
11秒前
12秒前
NIER完成签到,获得积分20
12秒前
胡家裕完成签到 ,获得积分10
13秒前
顾矜应助和谐的洋葱采纳,获得10
13秒前
盛欢发布了新的文献求助20
13秒前
luckysame发布了新的文献求助10
14秒前
完美世界应助Netsky采纳,获得10
14秒前
高分求助中
(应助此贴封号)【重要!!请各用户(尤其是新用户)详细阅读】【科研通的精品贴汇总】 10000
Acute Mountain Sickness 2000
Handbook of Milkfat Fractionation Technology and Application, by Kerry E. Kaylegian and Robert C. Lindsay, AOCS Press, 1995 1000
A novel angiographic index for predicting the efficacy of drug-coated balloons in small vessels 500
Textbook of Neonatal Resuscitation ® 500
The Affinity Designer Manual - Version 2: A Step-by-Step Beginner's Guide 500
Affinity Designer Essentials: A Complete Guide to Vector Art: Your Ultimate Handbook for High-Quality Vector Graphics 500
热门求助领域 (近24小时)
化学 医学 生物 材料科学 工程类 有机化学 内科学 生物化学 物理 计算机科学 纳米技术 遗传学 基因 复合材料 化学工程 物理化学 病理 催化作用 免疫学 量子力学
热门帖子
关注 科研通微信公众号,转发送积分 5068023
求助须知:如何正确求助?哪些是违规求助? 4289750
关于积分的说明 13365025
捐赠科研通 4109504
什么是DOI,文献DOI怎么找? 2250387
邀请新用户注册赠送积分活动 1255727
关于科研通互助平台的介绍 1188244