[Resource Topic] 2017/158: Passphone: Outsourcing Phone-based Web Authentication while Protecting User Privacy

Welcome to the resource topic for 2017/158

Title:
Passphone: Outsourcing Phone-based Web Authentication while Protecting User Privacy

Authors: Martin Potthast, Christian Forler, Eik List, Stefan Lucks

Abstract:

This work introduces PassPhone, a new smartphone-based authentication scheme that outsources user verification to a trusted third party without sacrificing privacy: neither can the trusted third party learn the relation between users and service providers, nor can service providers learn those of their users to others. When employed as a second factor in conjunction with, for instance, passwords as a first factor, our scheme maximizes the deployability of two-factor authentication for service providers while maintaining user privacy. We conduct a twofold formal analysis of our scheme, the first regarding its general security, and the second regarding anonymity and unlinkability of its users. Moreover, we provide an automatic analysis using AVISPA, a comparative evaluation to existing schemes under Bonneau et al.'s framework, and an evaluation of a prototypical implementation.

ePrint: https://eprint.iacr.org/2017/158

See all topics related to this paper.

Feel free to post resources that are related to this paper below.

Example resources include: implementations, explanation materials, talks, slides, links to previous discussions on other websites.

For more information, see the rules for Resource Topics .