True2F: Backdoor-resistant authentication tokens

10/10/2018
by   Emma Dauterman, et al.
0

We present True2F, a system for second-factor authentication that provides the benefits of conventional authentication tokens in the face of phishing and software compromise, while also providing strong protection against token faults and backdoors. To do so, we develop new lightweight two-party protocols for generating cryptographic keys and ECDSA signatures, and we implement new privacy defenses to prevent cross-origin token-fingerprinting attacks. To facilitate real-world deployment, our system is backwards-compatible with today's U2F-enabled web services and runs on commodity hardware tokens after a firmware modification. A True2F-protected authentication takes just 57ms to complete on the token, compared with 23ms for unprotected U2F.

READ FULL TEXT

page 1

page 2

page 13

research
05/17/2022

How Not to Handle Keys: Timing Attacks on FIDO Authenticator Privacy

This paper presents a timing attack on the FIDO2 (Fast IDentity Online) ...
research
07/29/2018

Trust Based Identity Sharing For Token Grants

Authentication and authorization are two key elements of a software appl...
research
12/05/2021

Provisioning Fog Services to 3GPP Subscribers: Authentication and Application Mobility

Multi-Access Edge computing (MEC) and Fog computing provide services to ...
research
08/10/2022

Multi-Factor Key Derivation Function (MFKDF)

We present the first general construction of a Multi-Factor Key Derivati...
research
07/07/2020

WLCG Authorisation from X.509 to Tokens

The WLCG Authorisation Working Group was formed in July 2017 with the ob...
research
12/16/2021

Federated 3GPP Mobile Edge Computing Systems: A Transparent Proxy for Third Party Authentication with Application Mobility Support

Multi-Access or Mobile Edge Computing (MEC) is being deployed by 4G/5G o...
research
02/07/2019

Distributed Ledger Privacy: Ring Signatures, Möbius and CryptoNote

Distributed ledger and blockchain systems are expected to make financial...

Please sign up or login with your details

Forgot password? Click here to reset