Skip to main navigation Skip to search Skip to main content

A new secure authentication scheme for web login using BLE smart devices

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

5 Scopus citations

Abstract

Existing user authentication schemes used for login to a website are incapable of handling recent phishing attacks such as real time (RT) / control relay (CR) man in the middle (MITM) attack and attacks launched via covertly installed malicious browser extensions (MEs). Two factor authentication schemes such as Google 2 Step verification, SAASPASS, QR code, graphical password and push notification based login schemes can be compromised using RT / CR MITM phishing attacks. Hardware token based schemes are safe but the extra cost of the hardware token makes them unattractive to users. Therefore, there is a need to develop new authentication schemes which are hard for an attacker to compromise but easy for users to understand and utilize. This paper analyzes existing authentication schemes to identify the research gaps and then proposes a secure authentication scheme which uses Bluetooth Low Energy (BLE, BT 4.0+ version) devices for user identification and which can handle RT/CR MITM phishing attacks, attacks launched via malicious browser extensions and app spoofing via attackers. The proposed scheme is location/client system independent and is secure from Bluetooth address spoofing attacks.

Original languageEnglish
Title of host publicationProceedings of 2017 11th IEEE International Conference on Anti-Counterfeiting, Security, and Identification, ASID 2017
EditorsJianyang Zhou, Donghui Guo, Jiyang Dong
PublisherIEEE Computer Society
Pages95-98
Number of pages4
ISBN (Electronic)9781538605325
DOIs
StatePublished - Jul 2 2017
Event11th IEEE International Conference on Anti-Counterfeiting, Security, and Identification, ASID 2017 - Xiamen, China
Duration: Oct 27 2017Oct 29 2017

Publication series

NameProceedings of the International Conference on Anti-Counterfeiting, Security and Identification, ASID
Volume2017-October

Conference

Conference11th IEEE International Conference on Anti-Counterfeiting, Security, and Identification, ASID 2017
Country/TerritoryChina
CityXiamen
Period10/27/1710/29/17

Keywords

  • Authentication
  • BLE
  • Bluetooth
  • Login
  • Malicious browser extension
  • Phishing

Fingerprint

Dive into the research topics of 'A new secure authentication scheme for web login using BLE smart devices'. Together they form a unique fingerprint.

Cite this