DocumentCode
3091923
Title
The Mobile Phone as a Multi OTP Device Using Trusted Computing
Author
Alzomai, Mohammed ; Jøsang, Audun
Author_Institution
Queensland Univ. of Technol., Brisbane, QLD, Australia
fYear
2010
fDate
1-3 Sept. 2010
Firstpage
75
Lastpage
82
Abstract
The rapid growth in the number of online services leads to an increasing number of different digital identities each user needs to manage. As a result, many people feel overloaded with credentials, which in turn negatively impacts their ability to manage them securely. Passwords are perhaps the most common type of credential used today. To avoid the tedious task of remembering difficult passwords, users often behave less securely by using low entropy and weak passwords. Weak passwords and bad password habits represent security threats to online services. Some solutions have been developed to eliminate the need for users to create and manage passwords. A typical solution is based on giving the user a hardware token that generates one-time-passwords, i.e. passwords for single session or transaction usage. Unfortunately, most of these solutions do not satisfy scalability and/or usability requirements, or they are simply insecure. In this paper, we propose a scalable OTP solution using mobile phones and based on trusted computing technology that combines enhanced usability with strong security.
Keywords
message authentication; mobile computing; mobile phone; multi OTP device; one-time-passwords; online services; security threats; trusted computing; weak passwords; Authentication; Generators; Hardware; Mobile handsets; Public key; Software; Authentication; OTP; OTP tokens; identity management; mobile phone; trusted computing; usability;
fLanguage
English
Publisher
ieee
Conference_Titel
Network and System Security (NSS), 2010 4th International Conference on
Conference_Location
Melbourne, VIC
Print_ISBN
978-1-4244-8484-3
Electronic_ISBN
978-0-7695-4159-4
Type
conf
DOI
10.1109/NSS.2010.39
Filename
5636068
Link To Document