Enhanced Multi-factor Out-of-Band Authentication En Route to Securing SMS-based OTP

被引:0
|
作者
Reyes, Ariel Roy L. [1 ]
Festijo, Enrique D. [2 ]
Medina, Ruji P. [1 ]
机构
[1] Technol Inst Philippines, Grad Programs, Quezon City, Philippines
[2] Technol Inst Philippines, Manila, Philippines
关键词
Blowfish-128; eavesdropping; SMiShing; SMS-based OTP; USER AUTHENTICATION;
D O I
暂无
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
Validation of user's authenticity through authentication played a crucial role to address risks and security issues in today's connected world. Among different authentication methods, OTP sent via SMS was identified as the most commonly used multi-factor authentication mechanism However, studies have shown that it has not remained attack-proof. It has been branded to be vulnerable to SMiShing, a technique comparable to Internet phishing, and Eavesdropping accomplished through keylogging, screens capturing, shoulder surfing and other social engineering practices. This study introduced an innovative approach to secure SMS-based OTP against its threats through OTP encryption using modified Blowfish algorithm. A mobile application was also employed for capturing and processing encrypted SMS-based OTP to produce new OTP for verification, thus performing end-to-end OTP. Experimentation results and analysis revealed that the proposed architecture was free against the said vulnerabilities and promote tighter security, making it a good alternative for SMS based OTP multi-factor authentication.
引用
收藏
页码:145 / 154
页数:10
相关论文
共 6 条
  • [1] SMS OTP Security (SOS): Hardening SMS-Based Two Factor Authentication
    Peeters, Christian
    Patton, Christopher
    Munyaka, Imani N. S.
    Olszewski, Daniel
    Shrimpton, Thomas
    Traynor, Patrick
    [J]. ASIA CCS'22: PROCEEDINGS OF THE 2022 ACM ASIA CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, 2022, : 2 - 16
  • [2] An efficient multi-factor authentication scheme based CNNs for securing ATMs over cognitive-IoT
    Shalaby, Ahmed
    Gad, Ramadan
    Hemdan, Ezz El-Din
    El-Fishawy, Nawal
    [J]. PEERJ COMPUTER SCIENCE, 2021, : 1 - 28
  • [3] BAuth-ZKP-A Blockchain-Based Multi-Factor Authentication Mechanism for Securing Smart Cities
    Ahmad, Md. Onais
    Tripathi, Gautami
    Siddiqui, Farheen
    Alam, Mohammad Afshar
    Ahad, Mohd Abdul
    Akhtar, Mohd Majid
    Casalino, Gabriella
    [J]. SENSORS, 2023, 23 (05)
  • [4] A Novel Robust Geolocation-Based Multi-Factor Authentication Method for Securing ATM Payment Transactions
    Alabdulatif, Abdullah
    Samarasinghe, Rohan
    Thilakarathne, Navod Neranjan
    [J]. APPLIED SCIENCES-BASEL, 2023, 13 (19):
  • [5] Enhanced Cryptocurrency Security by Time-Based Token Multi-Factor Authentication Algorithm
    Abu Taher, Kazi
    Nahar, Tahmin
    Hossain, Syed Akhter
    [J]. 2019 1ST INTERNATIONAL CONFERENCE ON ROBOTICS, ELECTRICAL AND SIGNAL PROCESSING TECHNIQUES (ICREST), 2019, : 308 - 312
  • [6] Quantum-attack-resilience OTP-based multi-factor mutual authentication and session key agreement scheme for mobile users
    Basu, Swagatam
    Islam, S. K. Hafizul
    [J]. COMPUTERS & ELECTRICAL ENGINEERING, 2024, 119