The Good, the Bad and the (Not So) Ugly of Out-of-Band Authentication with eID Cards and Push Notifications: Design, Formal and Risk Analysis


연구 분야: Cryptography



학회: CODASPY '20: Proceedings of the Tenth ACM Conference on Data and Application Security and Privacy


초록

Everyday life is permeated by new technologies allowing people to perform almost any kind of operation from their smart devices. Although this is amazing from a convenience perspective, it may result in several security issues concerning the need for authenticating users in a proper and secure way. Electronic identity cards (also called eID cards) play a very important role in this regard, due to the high level of assurance they provide in identification and authentication processes. However, authentication solutions relying on them are still uncommon and suffer from many usability limitations. In this paper, we thus present the design and implementation of a novel passwordless, multi-factor authentication protocol based on eID cards. To reduce known usability issues while keeping a high level of security, our protocol leverages push notifications and mobile devices equipped with NFC, which can be used to interact with eID cards. In addition, we evaluate the security of the protocol through a formal security analysis and a risk analysis, whose results emphasize the acceptable level of security.


Author Profile
Marco Pernpruner

Fondazione Bruno Kessler Trento Italy

Italy
Author Profile
Roberto Carbone

Fondazione Bruno Kessler Trento Italy

Italy
Author Profile
Silvio Ranise

Fondazione Bruno Kessler Trento Italy

Italy

📄 논문 정보

발행 연도 2020년
인용수 3
출판 국가 Italy
사이트 ACM
좋아요 수 0

연관 논문 목록 (359건)