Trustware: A Device-based Protocol for Verifying Client Legitimacy

11/05/2017
by   Ben Doyle, et al.
0

Online services commonly attempt to verify the legitimacy of users with CAPTCHAs. However, CAPTCHAs are annoying for users, often difficult for users to solve, and can be defeated using cheap labor or, increasingly, with improved algorithms. We propose a new protocol for clients to prove their legitimacy, allowing the client's devices to vouch for the client. The client's devices, and those in close proximity, provide a one-time passcode that is verified by the device manufacturer. This verification proves that the client has physical access to expensive and trusted devices, vouching for the client's legitimacy.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
08/04/2022

A Forward-secure Efficient Two-factor Authentication Protocol

Two-factor authentication (2FA) schemes that rely on a combination of kn...
research
07/20/2020

CACTI: Captcha Avoidance via Client-side TEE Integration

Preventing abuse of web services by bots is an increasingly important pr...
research
01/29/2023

Unified Singular Protocol Flow for OAuth (USPFO) Ecosystem

OAuth 2.0 is a popular authorization framework that allows third-party c...
research
04/02/2019

DNS-Morph: UDP-Based Bootstrapping Protocol For Tor

Tor is one of the most popular systems for anonymous communication and c...
research
02/14/2018

Internet Location Verification: Challenges and Solutions

This thesis addresses the problem of verifying the geographic locations ...
research
06/06/2003

The FRED Event Display: an Extensible HepRep Client for GLAST

A new graphics client prototype for the HepRep protocol is presented. Ba...
research
11/27/2020

IntegriScreen: Visually Supervising Remote User Interactions on Compromised Clients

Remote services and applications that users access via their local clien...

Please sign up or login with your details

Forgot password? Click here to reset