2012
DOI: 10.1007/978-3-642-29336-8_2
|View full text |Cite
|
Sign up to set email alerts
|

Secure, Consumer-Friendly Web Authentication and Payments with a Phone

Abstract: Abstract. This paper proposes a challenge-response authentication system for web applications called Snap2Pass that is easy to use, provides strong security guarantees, and requires no browser extensions. The system uses QR codes which are small two-dimensional pictures that encode digital data. When logging in to a site, the web server sends the PC browser a QR code that encodes a cryptographic challenge; the user takes a picture of the QR code with his cell phone camera which results in a cryptographic respo… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

0
30
1

Year Published

2012
2012
2017
2017

Publication Types

Select...
6
3

Relationship

0
9

Authors

Journals

citations
Cited by 36 publications
(31 citation statements)
references
References 13 publications
0
30
1
Order By: Relevance
“…A similar approach to our solution is presented in [8]. However, there are two important differences.…”
Section: Comparison With Other Solutionsmentioning
confidence: 99%
See 1 more Smart Citation
“…A similar approach to our solution is presented in [8]. However, there are two important differences.…”
Section: Comparison With Other Solutionsmentioning
confidence: 99%
“…First, our solution allows the use of multiple identity providers. Moreover, in [8] the user has to go through an unverifiable registration process for each service. This approach also implies long-term storage of the user's data by the service provider, which increases the risk of information loss and privacy breaches.…”
Section: Comparison With Other Solutionsmentioning
confidence: 99%
“…For example, mobile phones can be used as the hardware token for one-time password generation. Dodson et al [9] suggested a challenge-response authentication system which involves a user snapping a picture of a QR code with a mobile device. The data from this marker generated encrypted data that were used during login.…”
Section: B Multifactor Authentication Schemesmentioning
confidence: 99%
“…Ben Dodson et al [9] proposed Snap2Pass, a mobile based authentication system that aims at replacing the traditional password-based web authentication; leveraging either RSA model or symmetric key encryption. Snap2Pass is based on the challenge-response authentication model; where the server sends a challenge (encrypted token) to the user encapsulated with a QR code, who in turn needs to scan, decrypt and send it back to the server for identity verification.…”
Section: Related Workmentioning
confidence: 99%