Loxin – A Universal Solution to Password-Free Login
نویسندگان
چکیده
As the easiest and cheapest way of authenticating an end user, password based approach has been consistently chosen by implementers of every new computer or mobile device based web service. Unfortunately, the explosive growth of web applications has made it impossible for users to manage dozens of passwords for accessing different web services. The situation is even worse considering the potential application of massively parallel computational devices such as general purpose GPUs and FPGA arrays for efficient password cracking. Hence, from a usability viewpoint, passwords have reached the end of their useful life. Motivated by a number of recent industry initiatives for online authentication, we present Loxin, an innovative and universal solution for password-free login. Loxin aims to improve on passwords with respect to both usability and security. Loxin takes advantages of popular push message services on mobile devices and enables users to access multiple web services using preowned identities such as email addresses in the system together with few taps on their mobile devices. In particular, the Loxin server cannot generate users’ login credentials for web access, thereby eliminating the potential risk of server compromise. The security analysis shows that Loxin is resistant to the most common attacks on web services such as replay attacks, manin-the-middle attacks, and server compromise attacks. The application of the Loxin security framework to the recent MintChip Challenge demonstrates the power of Loxin for building a real-world password-free mobile payment solution.
منابع مشابه
Loxin - A solution to password-less universal login
As the easiest and cheapest way of authenticating an end user, password based authentication methods have been consistently chosen by almost every new cloud service. Unfortunately, the explosive growth of cloud services and web applications has made it impossible for users to manage dozens of passwords for accessing different cloud services. The situation is even worse considering the potential...
متن کاملPassword-Free Login
Password-free login is a system that sets the user free from remembering the passwords used, so that the user can get an easy access to any website of his choice in a common password. The system is basically a password storage website that keeps all the login id's and password in a single database. The advantage of the system is that even if in mere future the user happens to forget the lo...
متن کاملCryptanalysis of a Novel Remote User Authentication Scheme
In 2005, Manik et al. [5] propose a novel remote user authentication scheme using bilinear pairings which allows a valid user to login to the remote system but prohibits too many users to login with the same login-ID. It also provides a flexible password change function. In the same year Chou et al.’s [3] proposed an impersonation attack on their user authentication scheme and also proposed the...
متن کاملRootkits for JavaScript Environments
A number of commercial cloud-based password managers use bookmarklets to automatically populate and submit login forms. Unfortunately, an attacker web site can maliciously alter the JavaScript environment and, when the login bookmarklet is invoked, steal the user’s passwords. We describe general attack techniques for altering a bookmarklet’s JavaScript environment and apply them to extracting p...
متن کاملDoodles for Authentication: Recognition and User Study Results
Traditional means of computer based authentication based on username and password combinations become unwieldy as the number of password accounts one manages increases. The average computer user needs to remember a large number of text username and password combinations for different applications, which places a large cognitive load on the user. While biometric login based systems can free the ...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2013