• DocumentCode
    3575143
  • Title

    Out-of-Band Authentication Model with Hashcash Brute-Force Prevention

  • Author

    Violaris, George ; Dionysiou, Ioanna

  • Author_Institution
    Sch. of Eng. & Inf. Sci., Middlesex Univ., London, UK
  • fYear
    2014
  • Firstpage
    794
  • Lastpage
    801
  • Abstract
    Successful out-of-band authentication in popular languages such as PHP has proven to be problematic and in many ways unsafe as dynamically typed languages allow for more than one ways of doing things, and the standards set out are usually not followed. It is true that out-of-band authentication using SMS messaging enhances the security of simple passwords specified by users, however many times the handling of the One-Time-Passwords (OTP) on the server side is done with disregard of the ways an attacker can bypass the requirement for such a feature. It is therefore essential to find ways which the OTP cannot be brute-forced or circumvented, by providing mechanisms such as automatic purging of OTPs from the database and enhancing the safety of the server traffic handling as well as the HTTP form submission requests and responses with a library known as Hash cash. By using this method, a potential attacker would be met by a time-consuming challenge, which would leave any sort of brute-force, denial of service or requirement circumvention attacks impractical for gaining access to a PHP login system. Furthermore, the usage of Hash cash for credential retransmission and re-authentication for vital aspects of the user´s workflow while authenticated, make such as system much more impenetrable than using simple out-of-band or other two-factor authentication schemes.
  • Keywords
    cryptography; electronic messaging; message authentication; HTTP; PHP login system; SMS messaging; brute-forced OTP; circumvented OTP; denial of service; dynamically typed language; hash cash; hashcash brute-force prevention; one-time-passwords; out-of-band authentication model; requirement circumvention attack; server traffic handling; Authentication; Databases; Electronic mail; Mobile communication; Mobile handsets; Servers;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    High Performance Computing and Communications, 2014 IEEE 6th Intl Symp on Cyberspace Safety and Security, 2014 IEEE 11th Intl Conf on Embedded Software and Syst (HPCC,CSS,ICESS), 2014 IEEE Intl Conf on
  • Print_ISBN
    978-1-4799-6122-1
  • Type

    conf

  • DOI
    10.1109/HPCC.2014.133
  • Filename
    7056834