Let's Authenticate: Automated Certificates for User Authentication

6Citations
Citations of this article
10Readers
Mendeley users who have this article in their library.

Abstract

Passwords have numerous drawbacks, and as a result many systems have been designed to replace them. Password replacements have generally failed to dislodge passwords due to the complexity of balancing usability, deployability, and security. However, despite this lack of success, recent advances with password managers and FIDO2 afford new opportunities to explore system design for password replacements. In this work, we explore the feasibility of a system for user authentication based on certificates. Rather than developing new cryptography, we develop a new system, called Let's Authenticate, which combines elements of password managers, FIDO2, and certificates. Our design incorporates feedback from a survey of 397 participants to understand their preferences for system features. Let's Authenticate issues privacy-preserving certificates to users, automatically manages their credentials, and eliminates trust in third parties. We provide a detailed security and privacy analysis, an overhead analysis, and a systematic comparison of the system to a variety of alternatives using a well-known framework. We discuss how Let's Authenticate compares to other systems, lessons learned from our design, and issues related to centralized management of authentication data.

Cite

CITATION STYLE

APA

Conners, J., Derbidge, S., Devenport, C., Farnsworth, N., Gates, K., Lambert, S., … Zappala, D. (2022). Let’s Authenticate: Automated Certificates for User Authentication. In 29th Annual Network and Distributed System Security Symposium, NDSS 2022. The Internet Society. https://doi.org/10.14722/ndss.2022.24272

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free