Stronger Authentication for Password Credential Internet Services
Number of Authors: 22017 (English)In: Proceedings of the 2017 Third Conference on Mobile and Secure Services (MOBISECSERV) / [ed] Pascal Urien, Selwyn Piramuthu, Piscataway, NJ: IEEE conference proceedings, 2017, p. 41-45, article id 7886566Conference paper, Published paper (Refereed)
Abstract [en]
Most Web and other on-line service providers (”Inter- net Services”) only support legacy ID (or email) and password (ID/PW) credential authentication. However, there are numerous vulnerabilities concerning ID/PW credentials. Scholars and the industry have proposed several improved security solutions, such as MFA, however most of the Internet Services have refused to adopt these solutions. Mobile phones are much more sensitive to these vulnerabilities (so this paper focuses on mobile phones). Many users take advantage of password managers, to keep track of all their Internet Service profiles. However, the Internet Service profiles found in password managers, are normally kept on the PC or mobile phone’s disk, in an encrypted form. Our first contribution is a design guideline, whereby the Internet Service profiles never need to touch the client’s disk. Most users would benefit, if they had the ability to use MFA, to login to a legacy Internet Service, which only supports ID/PW credential authentication. Our second contribution is a design guideline, whereby users can choose, for each legacy ID/PW Internet Service, which specific MFA they wish to use. We have also presenting conceptual design guidelines, showing that both of our contributions are minor changes to existing password managers, which can be implemented easily with low overhead.
Place, publisher, year, edition, pages
Piscataway, NJ: IEEE conference proceedings, 2017. p. 41-45, article id 7886566
Keywords [en]
Mobile Device Management, Security, Credentials, Android, Identification, Authentication, Password, Stormpath
National Category
Computer Sciences Information Systems, Social aspects Computer and Information Sciences
Research subject
Information systems; Pervasive Mobile Computing; Centre - Centre for Critical Infrastructure and Societal Security (CISS)
Identifiers
URN: urn:nbn:se:ltu:diva-61952DOI: 10.1109/MOBISECSERV.2017.7886566ISI: 000403395200008Scopus ID: 2-s2.0-85018333420ISBN: 978-1-5090-3632-5 (electronic)OAI: oai:DiVA.org:ltu-61952DiVA, id: diva2:1073594
Conference
3rd Conference On Mobile And Secure Services, Miami Beach, FL, 11-12 February 2017
Projects
Centre for Critical Infrastructure and Societal Security2017-02-112017-02-112025-10-22Bibliographically approved