File Download

There are no files associated with this item.

  Links for fulltext
     (May Require Subscription)
Supplementary

Article: WebCallerID: Leveraging cellular networks for Web authentication

TitleWebCallerID: Leveraging cellular networks for Web authentication
Authors
KeywordsAuthentication
cellular networks
mobile authentication
OpenID
phishing
single sign on
usable security
Web authentication
Issue Date2011
Citation
Journal of Computer Security, 2011, v. 19, n. 5, p. 869-893 How to Cite?
AbstractWeb authentication that is both secure and usable remains a challenge. Passwords are vulnerable to phishing attacks, while physical tokens face deployment obstacles. We propose to leverage the authentication infrastructure of cellular networks to enhance Web authentication. We design WebCallerID, a Web authentication scheme that uses cell phones as physical tokens and uses cellular networks as trusted identity providers. Since WebCallerID requires no user participation during authentication, it prevents security mistakes by users. WebCallerID also prevents rogue websites from replaying authentication assertions or stealing users' identities. We have implemented a prototype of WebCallerID using the OpenID framework. The prototype shows that WebCallerID seamlessly integrates into OpenID-capable Web authentication while avoiding phishing problems in OpenID and simplifying user participation. © 2011-IOS Press and the authors. All rights reserved.
Persistent Identifierhttp://hdl.handle.net/10722/346559
ISSN
2023 Impact Factor: 0.9
2023 SCImago Journal Rankings: 0.340

 

DC FieldValueLanguage
dc.contributor.authorHsu, Francis-
dc.contributor.authorChen, Hao-
dc.contributor.authorMacHiraju, Sridhar-
dc.date.accessioned2024-09-17T04:11:43Z-
dc.date.available2024-09-17T04:11:43Z-
dc.date.issued2011-
dc.identifier.citationJournal of Computer Security, 2011, v. 19, n. 5, p. 869-893-
dc.identifier.issn0926-227X-
dc.identifier.urihttp://hdl.handle.net/10722/346559-
dc.description.abstractWeb authentication that is both secure and usable remains a challenge. Passwords are vulnerable to phishing attacks, while physical tokens face deployment obstacles. We propose to leverage the authentication infrastructure of cellular networks to enhance Web authentication. We design WebCallerID, a Web authentication scheme that uses cell phones as physical tokens and uses cellular networks as trusted identity providers. Since WebCallerID requires no user participation during authentication, it prevents security mistakes by users. WebCallerID also prevents rogue websites from replaying authentication assertions or stealing users' identities. We have implemented a prototype of WebCallerID using the OpenID framework. The prototype shows that WebCallerID seamlessly integrates into OpenID-capable Web authentication while avoiding phishing problems in OpenID and simplifying user participation. © 2011-IOS Press and the authors. All rights reserved.-
dc.languageeng-
dc.relation.ispartofJournal of Computer Security-
dc.subjectAuthentication-
dc.subjectcellular networks-
dc.subjectmobile authentication-
dc.subjectOpenID-
dc.subjectphishing-
dc.subjectsingle sign on-
dc.subjectusable security-
dc.subjectWeb authentication-
dc.titleWebCallerID: Leveraging cellular networks for Web authentication-
dc.typeArticle-
dc.description.naturelink_to_subscribed_fulltext-
dc.identifier.doi10.3233/JCS-2011-0424-
dc.identifier.scopuseid_2-s2.0-81255134913-
dc.identifier.volume19-
dc.identifier.issue5-
dc.identifier.spage869-
dc.identifier.epage893-

Export via OAI-PMH Interface in XML Formats


OR


Export to Other Non-XML Formats