Improving the Robustness of Wireless Device Pairing Using Hyphen-Delimited Numeric Comparison

Ambarish Karole, Nitesh Saxena
{"title":"Improving the Robustness of Wireless Device Pairing Using Hyphen-Delimited Numeric Comparison","authors":"Ambarish Karole, Nitesh Saxena","doi":"10.1109/NBiS.2009.57","DOIUrl":null,"url":null,"abstract":"The operation of achieving authenticated key agreement between two human-operated mobile devices over a short range wireless communication channel, such as Bluetooth or Wi-Fi, is known as \"pairing.\" The devices being paired are ad hoc in nature, i.e., they can not be assumed to have a prior context (such as pre-shared secrets) or a common trusted on- or off-line authority. However, the devices can generally be connected using auxiliary physical channel(s) (such as audio or visual) that can be authenticated by the user(s) of the devices. These authenticatable channels can thus be used to form a basis for pairing. One of the simplest pairing methods requires user to compare short (typically 4 digit long) numbers displayed on two devices. Prior usability studies investigating the numeric comparison method indicate that although users hardly ever reject matching numbers on two devices, a critical task of detecting non-matching numbers (and thus potential man-in-the-middle attacks) can be error-prone. In this paper, we propose a very simple and an intuitive method of employing \"hyphen-delimited\" numbers in device pairing. Our usability studies and analysis of test results show that the proposed method improves the robustness as well as usability of pairing based on numeric comparison.","PeriodicalId":312802,"journal":{"name":"2009 International Conference on Network-Based Information Systems","volume":"39 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2009-08-19","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2009 International Conference on Network-Based Information Systems","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/NBiS.2009.57","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

The operation of achieving authenticated key agreement between two human-operated mobile devices over a short range wireless communication channel, such as Bluetooth or Wi-Fi, is known as "pairing." The devices being paired are ad hoc in nature, i.e., they can not be assumed to have a prior context (such as pre-shared secrets) or a common trusted on- or off-line authority. However, the devices can generally be connected using auxiliary physical channel(s) (such as audio or visual) that can be authenticated by the user(s) of the devices. These authenticatable channels can thus be used to form a basis for pairing. One of the simplest pairing methods requires user to compare short (typically 4 digit long) numbers displayed on two devices. Prior usability studies investigating the numeric comparison method indicate that although users hardly ever reject matching numbers on two devices, a critical task of detecting non-matching numbers (and thus potential man-in-the-middle attacks) can be error-prone. In this paper, we propose a very simple and an intuitive method of employing "hyphen-delimited" numbers in device pairing. Our usability studies and analysis of test results show that the proposed method improves the robustness as well as usability of pairing based on numeric comparison.
使用连字符分隔的数字比较提高无线设备配对的鲁棒性
通过蓝牙或Wi-Fi等短距离无线通信通道,在两个人工操作的移动设备之间实现身份验证密钥协议的操作称为“配对”。正在配对的设备本质上是特别的,也就是说,不能假定它们具有先前的上下文(例如预共享的秘密)或公共可信的在线或离线权威。但是,设备通常可以使用辅助物理通道(如音频或视频)连接,这些通道可以由设备的用户进行身份验证。因此,这些可验证的通道可用于形成配对的基础。最简单的配对方法之一需要用户比较两个设备上显示的短(通常是4位长)号码。先前调查数字比较方法的可用性研究表明,尽管用户很少拒绝两个设备上的匹配数字,但检测不匹配数字(从而潜在的中间人攻击)的关键任务可能容易出错。在本文中,我们提出了一种非常简单和直观的方法,在设备配对中使用“连字符分隔”的数字。我们的可用性研究和测试结果分析表明,该方法提高了基于数值比较的配对的鲁棒性和可用性。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信