TruWalletM: Secure web authentication on mobile platforms

13Citations
Citations of this article
23Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Mobile phones are increasingly used as general purpose computing devices with permanent Internet connection. This imposes several threats as the phone operating system (OS) is typically derived from desktop counterparts and, hence, inherits the same or similar security shortcomings. In particular, the protection of login credentials when accessing web services becomes crucial under phishing and malware attacks. On the other hand many modern mobile phones provide hardware-supported security mechanisms currently unused by most phone OSs. In this paper, we show how to use these mechanisms, in particular trusted execution environments, to protect the user's login credentials. We present the design and implementation proposal (based on Nokia N900 mobile platform) of TruWalletM, a wallet-like password manager and authentication agent towards the protection of login credentials on a mobile phone without the need to trust the whole OS software. We preserve compatibility to existing standard web authentication mechanisms. © 2011 Springer-Verlag.

Cite

CITATION STYLE

APA

Bugiel, S., Dmitrienko, A., Kostiainen, K., Sadeghi, A. R., & Winandy, M. (2011). TruWalletM: Secure web authentication on mobile platforms. In Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics) (Vol. 6802 LNCS, pp. 219–236). https://doi.org/10.1007/978-3-642-25283-9_15

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free