• DocumentCode
    1335662
  • Title

    oPass: A User Authentication Protocol Resistant to Password Stealing and Password Reuse Attacks

  • Author

    Sun, Hung-Min ; Chen, Yao-Hsin ; Lin, Yue-Hsun

  • Author_Institution
    Dept. of Comput. Sci., Nat. Tsing Hua Univ., Hsinchu, Taiwan
  • Volume
    7
  • Issue
    2
  • fYear
    2012
  • fDate
    4/1/2012 12:00:00 AM
  • Firstpage
    651
  • Lastpage
    663
  • Abstract
    Text password is the most popular form of user authentication on websites due to its convenience and simplicity. However, users´ passwords are prone to be stolen and compromised under different threats and vulnerabilities. Firstly, users often select weak passwords and reuse the same passwords across different websites. Routinely reusing passwords causes a domino effect; when an adversary compromises one password, she will exploit it to gain access to more websites. Second, typing passwords into untrusted computers suffers password thief threat. An adversary can launch several password stealing attacks to snatch passwords, such as phishing, keyloggers and malware. In this paper, we design a user authentication protocol named oPass which leverages a user´s cellphone and short message service to thwart password stealing and password reuse attacks. oPass only requires each participating website possesses a unique phone number, and involves a telecommunication service provider in registration and recovery phases. Through oPass, users only need to remember a long-term password for login on all websites. After evaluating the oPass prototype, we believe oPass is efficient and affordable compared with the conventional web authentication mechanisms.
  • Keywords
    cryptographic protocols; message authentication; Web sites; oPass; password reuse attacks; password stealing; short message service; telecommunication service provider; text password; thwart password; user authentication protocol resistant; weak passwords; Authentication; Computers; Human factors; Protocols; Servers; Telecommunications; Network security; password reuse attack; password stealing attack; user authentication;
  • fLanguage
    English
  • Journal_Title
    Information Forensics and Security, IEEE Transactions on
  • Publisher
    ieee
  • ISSN
    1556-6013
  • Type

    jour

  • DOI
    10.1109/TIFS.2011.2169958
  • Filename
    6030929