基于qr码和网络摄像头的智能移动设备认证方案分析

IF 0.1 Q4 INTERNATIONAL RELATIONS
Oleksandr I. Kot, I. Svatovskiy
{"title":"基于qr码和网络摄像头的智能移动设备认证方案分析","authors":"Oleksandr I. Kot, I. Svatovskiy","doi":"10.26565/2304-6201-2020-47-04","DOIUrl":null,"url":null,"abstract":"The paper analyzes the necessity and expediency of using the method of user authentication based on QR-code and webcam for Smart-Mobile devices. Phishing attacks are one of the most serious threats faced by Internet users. Existing authentication schemes are not able to provide an adequate protection from these attacks, as evidenced by statistics collected by the companies researching cybersecurity. Therefore, the task of developing a secure authentication scheme for users, which can effectively counteract various types of phishing attacks is very important. The paper proposes a new authentication scheme for users, which allows them to log in to their accounts without remembering passwords or presenting other authentication tokens. According to the messaging protocol in the proposed scheme, the user must scan the dynamically generated QR-code using a smartphone application, then take their own photo via the webcam, and send it to the smartphone via a message from the server. Thus, the full authentication procedure requires minimal user involvement and is performed automatically. The results of evaluation and practical testing show that the proposed authentication scheme is quite reliable and can be used as a secure user authentication scheme for Smart-Mobile devices. The proposed authentication protocol is not only able to cope with attacks such as Real Time Man-In-The-Middle and Controlled Relay Man-In-The-Middle, but can also protect users from the effects of malicious browser extensions and substitution of authentic applications by malicious variants. In addition, the proposed scheme does not require users to have any authentication tokens or credentials, as all they need is to scan the QR-code and verify the image taken by their own webcam. That makes the use of the proposed scheme more convenient and easy for users as compared to other known authentication schemes. Currently, the application of the proposed scheme requires the use of HTTPS websites for the exchange of all data involved. Thus, the proposed protocol can be implemented to manage cookies securely in order to prevent the interception of session data.","PeriodicalId":53765,"journal":{"name":"Meridiano 47-Journal of Global Studies","volume":"83 1","pages":""},"PeriodicalIF":0.1000,"publicationDate":"2020-09-28","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"Analysis of the authentication scheme based on the use of QR-code and webcam for Smart-Mobile devices\",\"authors\":\"Oleksandr I. Kot, I. Svatovskiy\",\"doi\":\"10.26565/2304-6201-2020-47-04\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"The paper analyzes the necessity and expediency of using the method of user authentication based on QR-code and webcam for Smart-Mobile devices. Phishing attacks are one of the most serious threats faced by Internet users. Existing authentication schemes are not able to provide an adequate protection from these attacks, as evidenced by statistics collected by the companies researching cybersecurity. Therefore, the task of developing a secure authentication scheme for users, which can effectively counteract various types of phishing attacks is very important. The paper proposes a new authentication scheme for users, which allows them to log in to their accounts without remembering passwords or presenting other authentication tokens. According to the messaging protocol in the proposed scheme, the user must scan the dynamically generated QR-code using a smartphone application, then take their own photo via the webcam, and send it to the smartphone via a message from the server. Thus, the full authentication procedure requires minimal user involvement and is performed automatically. The results of evaluation and practical testing show that the proposed authentication scheme is quite reliable and can be used as a secure user authentication scheme for Smart-Mobile devices. The proposed authentication protocol is not only able to cope with attacks such as Real Time Man-In-The-Middle and Controlled Relay Man-In-The-Middle, but can also protect users from the effects of malicious browser extensions and substitution of authentic applications by malicious variants. In addition, the proposed scheme does not require users to have any authentication tokens or credentials, as all they need is to scan the QR-code and verify the image taken by their own webcam. That makes the use of the proposed scheme more convenient and easy for users as compared to other known authentication schemes. Currently, the application of the proposed scheme requires the use of HTTPS websites for the exchange of all data involved. Thus, the proposed protocol can be implemented to manage cookies securely in order to prevent the interception of session data.\",\"PeriodicalId\":53765,\"journal\":{\"name\":\"Meridiano 47-Journal of Global Studies\",\"volume\":\"83 1\",\"pages\":\"\"},\"PeriodicalIF\":0.1000,\"publicationDate\":\"2020-09-28\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Meridiano 47-Journal of Global Studies\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.26565/2304-6201-2020-47-04\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"Q4\",\"JCRName\":\"INTERNATIONAL RELATIONS\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Meridiano 47-Journal of Global Studies","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.26565/2304-6201-2020-47-04","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q4","JCRName":"INTERNATIONAL RELATIONS","Score":null,"Total":0}
引用次数: 0

摘要

分析了在智能移动设备中采用基于qr码和网络摄像头的用户认证方法的必要性和方便性。网络钓鱼攻击是互联网用户面临的最严重的威胁之一。正如研究网络安全的公司收集的统计数据所证明的那样,现有的身份验证方案无法提供足够的保护来抵御这些攻击。因此,开发一种安全的用户认证方案,有效地抵御各种类型的网络钓鱼攻击是非常重要的。本文提出了一种新的用户身份验证方案,该方案允许用户在不记住密码或提供其他身份验证令牌的情况下登录自己的帐户。根据该方案中的消息传递协议,用户必须使用智能手机应用程序扫描动态生成的qr码,然后通过网络摄像头拍摄自己的照片,并通过服务器的消息将其发送到智能手机。因此,完整的身份验证过程需要最少的用户参与,并且是自动执行的。评估和实际测试结果表明,所提出的认证方案具有较高的可靠性,可以作为智能移动设备的安全用户认证方案。所提出的认证协议不仅能够应对实时中间人和受控中继中间人等攻击,还可以保护用户免受恶意浏览器扩展和恶意变体替代真实应用程序的影响。此外,拟议的方案不要求用户拥有任何认证令牌或凭据,因为他们所需要的只是扫描qr码并验证他们自己的网络摄像头拍摄的图像。这使得与其他已知的身份验证方案相比,该方案的使用更加方便和容易。目前,拟议方案的应用要求使用HTTPS网站交换所有涉及的数据。因此,可以实现该协议来安全管理cookie,以防止会话数据被截获。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Analysis of the authentication scheme based on the use of QR-code and webcam for Smart-Mobile devices
The paper analyzes the necessity and expediency of using the method of user authentication based on QR-code and webcam for Smart-Mobile devices. Phishing attacks are one of the most serious threats faced by Internet users. Existing authentication schemes are not able to provide an adequate protection from these attacks, as evidenced by statistics collected by the companies researching cybersecurity. Therefore, the task of developing a secure authentication scheme for users, which can effectively counteract various types of phishing attacks is very important. The paper proposes a new authentication scheme for users, which allows them to log in to their accounts without remembering passwords or presenting other authentication tokens. According to the messaging protocol in the proposed scheme, the user must scan the dynamically generated QR-code using a smartphone application, then take their own photo via the webcam, and send it to the smartphone via a message from the server. Thus, the full authentication procedure requires minimal user involvement and is performed automatically. The results of evaluation and practical testing show that the proposed authentication scheme is quite reliable and can be used as a secure user authentication scheme for Smart-Mobile devices. The proposed authentication protocol is not only able to cope with attacks such as Real Time Man-In-The-Middle and Controlled Relay Man-In-The-Middle, but can also protect users from the effects of malicious browser extensions and substitution of authentic applications by malicious variants. In addition, the proposed scheme does not require users to have any authentication tokens or credentials, as all they need is to scan the QR-code and verify the image taken by their own webcam. That makes the use of the proposed scheme more convenient and easy for users as compared to other known authentication schemes. Currently, the application of the proposed scheme requires the use of HTTPS websites for the exchange of all data involved. Thus, the proposed protocol can be implemented to manage cookies securely in order to prevent the interception of session data.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
Meridiano 47-Journal of Global Studies
Meridiano 47-Journal of Global Studies INTERNATIONAL RELATIONS-
自引率
0.00%
发文量
19
审稿时长
12 weeks
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信