Softer smartcards usable cryptographic tokens with secure execution

5Citations
Citations of this article
27Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Cryptographic smartcards provide a standardized, interoperable way for multi-factor authentication. They bridge the gap between strong asymmetric authentication and short, user-friendly passwords (PINs) and protect long-term authentication secrets against malware and phishing attacks. However, to prevent malware from capturing entered PINs such cryptographic tokens must provide secure means for user input and output. This often makes their usage inconvenient, as dedicated input key pads and displays are expensive and do not integrate with mobile applications or public Internet terminals. The lack of user acceptance is perhaps best documented by the large variety of non-standard multi-factor authentication methods used in online banking. In this paper, we explore a novel compromise between tokens with dedicated card reader and USB or software-based solutions. We design and implement a cryptographic token using modern secure execution technology, resulting in a flexible, cost-efficient solution that is suitable for mobile use yet secure against common malware and phishing attacks. © 2012 Springer-Verlag.

Cite

CITATION STYLE

APA

Brasser, F. F., Bugiel, S., Filyanov, A., Sadeghi, A. R., & Schulz, S. (2012). Softer smartcards usable cryptographic tokens with secure execution. In Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics) (Vol. 7397 LNCS, pp. 329–343). https://doi.org/10.1007/978-3-642-32946-3_24

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free