SMS OTP Security (SOS): Hardening SMS-Based Two Factor Authentication

被引:8
|
作者
Peeters, Christian [1 ]
Patton, Christopher [1 ]
Munyaka, Imani N. S. [1 ]
Olszewski, Daniel [1 ]
Shrimpton, Thomas [1 ]
Traynor, Patrick [1 ]
机构
[1] Univ Florida, Gainesville, FL 32611 USA
基金
美国国家科学基金会;
关键词
security; two-factor authentication; cellular; SMS; authenticated key-exchange; USER PERCEPTIONS;
D O I
10.1145/3488932.3497756
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
SMS-based two-factor authentication (2FA) is the most widely deployed 2FA mechanism, despite the fact that SMS messages are known to be vulnerable to rerouting attacks, and despite the availability of alternatives that may be more secure. This is for two reasons. First, it is very effective in practice, as evidenced by reports from Google and Microsoft. Second, users prefer SMS over alternatives, because text messaging is already part of their daily communication. Accepting this practical reality, we developed a new SMS-based protocol that makes rerouting attacks useless to adversaries who aim to take over user accounts. Our protocol delivers one-time passwords (OTP) via text message in a manner that adds minimal overhead (to both the user and the server) over existing SMS-based methods, and is implemented with only small changes to the stock text-message applications that already ship on mobile phones. The security of our protocol rests upon a provably secure authenticated key exchange protocol that, crucially, does not place significant new burdens upon the user. Indeed, we carry out a user study that demonstrates no statistically significant difference between traditional SMS and our protocol, in terms of usability.
引用
收藏
页码:2 / 16
页数:15
相关论文
共 50 条
  • [1] Device Risk Analysis Protocol for SMS-Based OTP Authentication
    Bartlomiejczyk, Maciej
    El Fray, Imed
    [J]. IEEE ACCESS, 2024, 12 : 123177 - 123192
  • [2] An Enhanced SMS-based OTP Scheme
    Zhou, Yonghe
    Hu, Liang
    Chu, Jianfeng
    [J]. PROCEEDINGS OF THE 2017 2ND INTERNATIONAL CONFERENCE ON AUTOMATION, MECHANICAL CONTROL AND COMPUTATIONAL ENGINEERING (AMCCE 2017), 2017, 118 : 1091 - 1094
  • [3] Enhanced Multi-factor Out-of-Band Authentication En Route to Securing SMS-based OTP
    Reyes, Ariel Roy L.
    Festijo, Enrique D.
    Medina, Ruji P.
    [J]. INTERNATIONAL JOURNAL OF ENGINEERING AND TECHNOLOGY INNOVATION, 2019, 9 (02) : 145 - 154
  • [4] Strengthening SMS-Based Authentication through Usability
    AlZomai, Mohammed
    Josang, Audun
    McCullagh, Adrian
    Foo, Ernest
    [J]. PROCEEDINGS OF THE 2008 INTERNATIONAL SYMPOSIUM ON PARALLEL AND DISTRIBUTED PROCESSING WITH APPLICATIONS, 2008, : 683 - +
  • [5] Security Analysis of SMS as a Second Factor of Authentication
    Jover, Roger Piqueras
    [J]. COMMUNICATIONS OF THE ACM, 2020, 63 (12) : 46 - 52
  • [6] Security Analysis of SMS as a Second Factor of Authentication
    Jover R.P.
    [J]. 1600, Association for Computing Machinery (18): : 37 - 60
  • [7] A Novel Protocol For the Security of SMS-Based Mobile Banking
    Abolghasemi, Meer Soheil
    Rezapour, Taha Yasin
    Atani, Reza Ebrahimi
    [J]. 2013 5TH CONFERENCE ON INFORMATION AND KNOWLEDGE TECHNOLOGY (IKT), 2013, : 97 - 101
  • [8] Resetting Your Password Is Vulnerable: A Security Study of Common SMS-Based Authentication in IoT Device
    Wang, Dong
    Zhang, Xiaosong
    Ming, Jiang
    Chen, Ting
    Wang, Chao
    Niu, Weina
    [J]. WIRELESS COMMUNICATIONS & MOBILE COMPUTING, 2018,
  • [9] The Trouble with SMS Two-Factor Authentication
    Kugler, Logan
    [J]. COMMUNICATIONS OF THE ACM, 2019, 62 (06) : 14 - 14
  • [10] Harnessing Electronic Signatures to Improve the Security of SMS-Based Services
    Zefferer, Thomas
    Tauber, Arne
    Zwattendorfer, Bernd
    [J]. WEB INFORMATION SYSTEMS AND TECHNOLOGIES, WEBIST 2012, 2013, 140 : 331 - 346