loading...
A mobile based approach to strong authentication on Web
Bucharest, Romania August 01-August 03
DOI Bookmark: http://doi.ieeecomputersociety.org/10.1109/ICCGI.2006.2International Multi-Conference on Com ...
 This Article 
 
PDF
HTML
IEEE Xplore Subscribers
 
 Share 
   
 Bibliographic References 
   
 Add to: 
 
Digg
Furl
Spurl
Blink
Simpy
Google
Del.icio.us
Y!MyWeb
 
 Search 
   
Gianluigi Me, University of Rome "Tor Vergata"
Daniele Pirro, University of Rome "Tor Vergata"
Roberto Sarrecchia, University of Rome "Tor Vergata"
The rapid increase of the phishing phenomenon states that the web authentication systems not based on One Time Password (OTP) are definitively ineffective in providing financial services. Existent web authentication systems have been developed on the classic username/password mechanism using a single channel, either mobile or web, generating an expensive or inadequate authentication system. The proposed solution is a combined web/mobile authentication system. The basic authentication mechanism is integrated with a challenge/response process and an OTP. The challenge is issued from an authentication server and has to authenticate a mobile device, typically a cell phone. This device can communicate with any other involved parts through a fixed terminal, typically a personal computer, via a Bluetooth connection. The mobile device, once accepted, performs the authentication with the web site or application. This final step is accomplished using a temporary one-time password.
Citation:
Gianluigi Me, Daniele Pirro, Roberto Sarrecchia, "A mobile based approach to strong authentication on Web," iccgi, pp.67, International Multi-Conference on Computing in the Global Information Technology - (ICCGI'06), 2006
Usage of this product signifies your acceptance of the Terms of Use.