Authenticating physical location using QR codes and network latency

Charles Allen, A. Harfield
{"title":"Authenticating physical location using QR codes and network latency","authors":"Charles Allen, A. Harfield","doi":"10.1109/JCSSE.2017.8025952","DOIUrl":null,"url":null,"abstract":"QR codes are increasingly being used as a mechanism to transmit one time passwords (OTPs) between devices for the purpose of authentication due to their convenience, low cost, and the ubiquity of consumer mobile devices. Existing practice typically utilizes a single QR code which is relatively easy to capture and relay to an offsite attacker or collaborator. We propose a mechanism using a stream of rapidly changing QR codes that maintains the convenience, ubiquity, and low cost of the standard approach, while aiming to eliminate the viability of relay attacks. We test this setup using a university class attendance scenario and successfully distinguish between valid physically present users and invalid offsite attackers.","PeriodicalId":6460,"journal":{"name":"2017 14th International Joint Conference on Computer Science and Software Engineering (JCSSE)","volume":"52 1","pages":"1-6"},"PeriodicalIF":0.0000,"publicationDate":"2017-07-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"5","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2017 14th International Joint Conference on Computer Science and Software Engineering (JCSSE)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/JCSSE.2017.8025952","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 5

Abstract

QR codes are increasingly being used as a mechanism to transmit one time passwords (OTPs) between devices for the purpose of authentication due to their convenience, low cost, and the ubiquity of consumer mobile devices. Existing practice typically utilizes a single QR code which is relatively easy to capture and relay to an offsite attacker or collaborator. We propose a mechanism using a stream of rapidly changing QR codes that maintains the convenience, ubiquity, and low cost of the standard approach, while aiming to eliminate the viability of relay attacks. We test this setup using a university class attendance scenario and successfully distinguish between valid physically present users and invalid offsite attackers.
使用QR码和网络延迟验证物理位置
由于QR码的便利性、低成本和消费者移动设备的普遍性,它越来越多地被用作设备之间传输一次性密码(otp)的机制,以达到认证的目的。现有的做法通常使用单个QR码,相对容易捕获并转发给场外攻击者或合作者。我们提出了一种使用快速变化的QR码流的机制,该机制保持了标准方法的便利性,普遍性和低成本,同时旨在消除中继攻击的可行性。我们使用大学课堂出勤场景测试了此设置,并成功区分了有效的物理在场用户和无效的场外攻击者。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信