Countering concurrent login attacks in 'Just Tap' push-based authentication: A redesign and usability evaluations

Jay Prakash, Clarice Chua Qing Yu, Tanvi Ravindra Thombre, Andrei Bytes, Mohammed Jubur, Nitesh Saxena, Lucienne Blessing, Jianying Zhou, Tony Q.S. Quek

Research output: Chapter in Book/Report/Conference proceedingConference contribution

4 Citations (Scopus)

Abstract

In this paper, we highlight a fundamental vulnerability associated with the widely adopted 'Just Tap' push-based authentication in the face of a concurrency attack, and propose the method REPLICATE, a redesign to counter this vulnerability. In the concurrency attack, the attacker launches the login session at the same time the user initiates a session, and the user may be fooled, with high likelihood, into accepting the push notification which corresponds to the attacker's session, thinking it is their own. The attack stems from the fact that the login notification is not explicitly mapped to the login session running on the browser in the Just Tap approach. REPLICATE attempts to address this fundamental flaw by having the user approve the login attempt by replicating the information presented on the browser session over to the login notification, such as by moving a key in a particular direction, choosing a particular shape, etc. We report on the design and a systematic usability study of REPLICATE. Even without being aware of the vulnerability, in general, participants placed multiple variants of REPLICATE in competition to the Just Tap and fairly above PIN-based authentication.

Original languageEnglish
Title of host publicationProceedings - 2021 IEEE European Symposium on Security and Privacy, Euro S and P 2021
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages21-36
Number of pages16
ISBN (Electronic)9781665414913
DOIs
Publication statusPublished - 2021 Sept
Event6th IEEE European Symposium on Security and Privacy, Euro S and P 2021 - Virtual, Online, Austria
Duration: 2021 Sept 62021 Sept 10

Publication series

NameProceedings - 2021 IEEE European Symposium on Security and Privacy, Euro S and P 2021

Conference

Conference6th IEEE European Symposium on Security and Privacy, Euro S and P 2021
Country/TerritoryAustria
CityVirtual, Online
Period21-09-0621-09-10

All Science Journal Classification (ASJC) codes

  • Computer Networks and Communications
  • Information Systems
  • Information Systems and Management
  • Safety, Risk, Reliability and Quality

Fingerprint

Dive into the research topics of 'Countering concurrent login attacks in 'Just Tap' push-based authentication: A redesign and usability evaluations'. Together they form a unique fingerprint.

Cite this