Passer à la navigation principale Passer à la recherche Passer au contenu principal

Introducing TLS-PSK Authentication for EMV devices

  • Pascal Urien

Résultats de recherche: Le chapitre dans un livre, un rapport, une anthologie ou une collectionContribution à une conférenceRevue par des pairs

Résumé

Access control to online banking accounts is a very critical topic for the always-on emerging society. In order to avoid phising threats resulting from classical mechanisms dealing with login and password tuples, the deployment of two-factor authentication tokens generating One Time Password (OTP) is recommended by many governmental organizations. A procedure based on EMV credit cards (the Chip Authentication Program) is proposed by several financial companies. However, due to passwords lifetime, OTP values may be collected by hackers via phishing attacks. In this paper we present a protocol that merges the CAP approach to the TLS-PSK protocol. As a consequence there is no need to collect OTP values, and phishing attacks don't work, because the mutual authentication between the card bearer and the WEB site is only performed via the SSL session.

langue originaleAnglais
titre2010 International Symposium on Collaborative Technologies and Systems, CTS 2010
Pages371-377
Nombre de pages7
Les DOIs
étatPublié - 16 juil. 2010
Evénement2010 International Symposium on Collaborative Technologies and Systems, CTS 2010 - Chicago, IL, États-Unis
Durée: 17 mai 201021 mai 2010

Série de publications

Nom2010 International Symposium on Collaborative Technologies and Systems, CTS 2010

Une conférence

Une conférence2010 International Symposium on Collaborative Technologies and Systems, CTS 2010
Pays/TerritoireÉtats-Unis
La villeChicago, IL
période17/05/1021/05/10

Empreinte digitale

Examiner les sujets de recherche de « Introducing TLS-PSK Authentication for EMV devices ». Ensemble, ils forment une empreinte digitale unique.

Contient cette citation