CICI: UCSS: Towards Secure and Usable Push Notification Authentication for Collaborative Scientific Infrastructures

CICI:UCSS:为协作科学基础设施实现安全可用的推送通知身份验证

基本信息

  • 批准号:
    2115107
  • 负责人:
  • 金额:
    $ 49.99万
  • 依托单位:
  • 依托单位国家:
    美国
  • 项目类别:
    Standard Grant
  • 财政年份:
    2021
  • 资助国家:
    美国
  • 起止时间:
    2021-08-15 至 2021-09-30
  • 项目状态:
    已结题

项目摘要

Second factor (2FA) or passwordless authentication based on notifications pushed to a user's personal device (e.g., a phone) that the user can simply approve (or deny) has become widely popular due to its convenience, especially to protect scientific resources at Universities and similar organizations. This project is studying the premise that the effortlessness of this approach gives rise to a fundamental design vulnerability arising from concurrent login sessions (one initiated by the user and the other initiated by the attacker), and then redesigning push-based authentication systems that can counter the identified vulnerability without degrading the overall usability of the approach. The proposed new design attempts to address the concurrent login attacks by establishing a unique binding between the user’s browser session and the push notification.The research consists of three inter-related activities: (1) formalization and study of a fundamental vulnerability against standard push notification authentication schemes; (2) design and implementation of low-effort push-based authentication schemes that can defeat the identified vulnerability without undermining the usability; and (3) formal studies of the proposed new push-based authentication schemes, conducted in lab settings and field environments. The developed resilient push authentication system designs are expected to offer an improved level of protection, accessibility and usability to everyday users in scientific and collaborative settings. The research prototypes are expected to be of broader value in future research on building resilient and usable authentication services in practice. The project is emphasizing technology transfer by working with major players in the push-based authentication domain. The proposed research is being integrated with educational activities in the form of advanced curriculum development and student mentoring in the broad domains of Authentication and Human-Computer Interaction, and the involvement of high school and K-12 students and minority populations are broadening the reach of the project.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
第二个因素(2FA)或无密码的身份验证,基于将用户的个人设备(例如手机)推向用户可以简单地批准(或拒绝)的通知,由于其便利性而变得广泛流行,尤其是为了保护大学和类似组织的科学资源。该项目正在研究以下前提:这种方法的毫无用处会导致并发登录会议引起的根本设计脆弱性(一个由用户启动,另一个由攻击者发起),然后重新设计了基于推动的身份验证系统,该系统可以在无需降解整个方法的整体可用性的情况下来抵消已确定的脆弱性。拟议的新设计试图通过在用户的浏览器会话和推送通知之间建立独特的绑定来解决并发登录攻击。该研究由三个相关活动组成:(1)格式化和研究针对标准推送通知认证方案的基本脆弱性; (2)设计和实施基于推动力的低及身份验证方案,这些方案可以定义确定的漏洞而不会破坏可用性; (3)对在实验室环境和现场环境中进行的拟议新的基于推动的身份验证方案的正式研究。预计开发的弹性推送身份验证系统设计将为我们的科学和协作环境中的每天用户提供改进的保护,可访问性和可用性。预计研究原型将在实践中建立弹性和可用身份验证服务的未来研究中具有更大的价值。该项目通过与基于推动的身份验证域中的主要参与者合作来强调技术转移。拟议的研究正在以高级课程发展和学生心态的形式与教育活动整合在一起,并在广泛的身份验证和人为计算机互动的领域,高中的参与以及K-12的学生和少数人群正在扩大该项目的范围。该奖项通过评估律师的范围来表现出众多的支持者,这一奖项对众所周知的构成构成了众多的影响力,这是一项伟大的支持者的范围。

项目成果

期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ monograph.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ sciAawards.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ conferencePapers.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ patent.updateTime }}

Nitesh Saxena其他文献

Gene Regulation and Species-Specific Evolution of Free Flight Odor Tracking in Drosophila
果蝇自由飞行气味追踪的基因调控和物种特异性进化
  • DOI:
    10.1093/molbev/msx241
  • 发表时间:
    2018
  • 期刊:
  • 影响因子:
    10.7
  • 作者:
    B. Houot;Laurie Cazalé;S. Fraichard;C. Everaerts;Nitesh Saxena;S. Sane;J. Ferveur
  • 通讯作者:
    J. Ferveur
PASSAT: Single Password Authenticated Secret-Shared Intrusion-Tolerant Storage with Server Transparency
PASSAT:具有服务器透明性的单密码验证秘密共享入侵容忍存储
  • DOI:
  • 发表时间:
    2021
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Kiavash Satvat;Maliheh Shirvanian;Nitesh Saxena
  • 通讯作者:
    Nitesh Saxena
Robust self-keying mobile ad hoc networks
强大的自键控移动自组织网络
  • DOI:
    10.1016/j.comnet.2006.07.009
  • 发表时间:
    2007
  • 期刊:
  • 影响因子:
    0
  • 作者:
    C. Castelluccia;Nitesh Saxena;J. Yi
  • 通讯作者:
    J. Yi
Towards Sensing-Enabled RFID Security and Privacy
迈向传感型 RFID 安全和隐私
Secure Device Pairing Based on a Visual Channel: Design and Usability Study
基于视觉通道的安全设备配对:设计和可用性研究

Nitesh Saxena的其他文献

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

{{ truncateString('Nitesh Saxena', 18)}}的其他基金

Collaborative Research: SaTC: CORE: Medium: Bubble Aid: Assistive AI to Improve the Robustness and Security of Reading Hand-Marked Ballots
合作研究:SaTC:核心:媒介:Bubble Aid:辅助人工智能提高阅读手写选票的稳健性和安全性
  • 批准号:
    2154507
  • 财政年份:
    2022
  • 资助金额:
    $ 49.99万
  • 项目类别:
    Continuing Grant
CICI: UCSS: Towards Secure and Usable Push Notification Authentication for Collaborative Scientific Infrastructures
CICI:UCSS:为协作科学基础设施实现安全可用的推送通知身份验证
  • 批准号:
    2139358
  • 财政年份:
    2021
  • 资助金额:
    $ 49.99万
  • 项目类别:
    Standard Grant
Collaborative Research: SaTC: TTP: Medium: Intrusion-Tolerant Outsourced Storage for Cyber-Infrastructure
协作研究:SaTC:TTP:中:网络基础设施的耐入侵外包存储
  • 批准号:
    2201465
  • 财政年份:
    2021
  • 资助金额:
    $ 49.99万
  • 项目类别:
    Standard Grant
SaTC: TTP: Small: SPHINX: A Password Store that Perfectly Hides Passwords from Itself
SaTC:TTP:小型:SPHINX:完美隐藏密码的密码存储
  • 批准号:
    2152669
  • 财政年份:
    2021
  • 资助金额:
    $ 49.99万
  • 项目类别:
    Standard Grant
Collaborative Research: SaTC: TTP: Medium: Intrusion-Tolerant Outsourced Storage for Cyber-Infrastructure
协作研究:SaTC:TTP:中:网络基础设施的耐入侵外包存储
  • 批准号:
    2030501
  • 财政年份:
    2020
  • 资助金额:
    $ 49.99万
  • 项目类别:
    Standard Grant
SaTC: TTP: Small: SPHINX: A Password Store that Perfectly Hides Passwords from Itself
SaTC:TTP:小型:SPHINX:完美隐藏密码的密码存储
  • 批准号:
    1714807
  • 财政年份:
    2017
  • 资助金额:
    $ 49.99万
  • 项目类别:
    Standard Grant
CICI: Secure Data Architecture: Improving the Security and Usability of Two-Factor Authentication for Cyberinfrastructure
CICI:安全数据架构:提高网络基础设施双因素身份验证的安全性和可用性
  • 批准号:
    1547350
  • 财政年份:
    2016
  • 资助金额:
    $ 49.99万
  • 项目类别:
    Standard Grant
TWC: Small: Collaborative: Spoof-Resistant Smartphone Authentication using Cooperating Wearables
TWC:小型:协作:使用协作可穿戴设备进行防欺骗智能手机身份验证
  • 批准号:
    1526524
  • 财政年份:
    2015
  • 资助金额:
    $ 49.99万
  • 项目类别:
    Standard Grant
EAGER: Establishing Secure Wireless Connections via Playful User Engagement
EAGER:通过有趣的用户参与建立安全的无线连接
  • 批准号:
    1255919
  • 财政年份:
    2012
  • 资助金额:
    $ 49.99万
  • 项目类别:
    Standard Grant
CT-ISG: User-Aided Secure Association of Wireless Devices
CT-ISG:用户辅助的无线设备安全关联
  • 批准号:
    1228236
  • 财政年份:
    2012
  • 资助金额:
    $ 49.99万
  • 项目类别:
    Standard Grant

相似海外基金

CICI: UCSS: Human-Centered Cybersecurity in Robotic Surgery (HCCRS) - Coordinating the Human and Cyber Infrastructure for Cybersecurity
CICI:UCCSS:机器人手术中以人为中心的网络安全 (HCCCS) - 协调网络安全的人力和网络基础设施
  • 批准号:
    2319891
  • 财政年份:
    2023
  • 资助金额:
    $ 49.99万
  • 项目类别:
    Standard Grant
CICI: UCSS: Trusted Resource Allocation in Volunteer Edge-Cloud Computing Workflows
CICI:UCSS:志愿者边缘云计算工作流程中的可信资源分配
  • 批准号:
    2232889
  • 财政年份:
    2023
  • 资助金额:
    $ 49.99万
  • 项目类别:
    Standard Grant
CICI:UCSS: ARMOR: Secure Querying of Massive Scientific Datasets
CICI:UCSS: ARMOR:海量科学数据集的安全查询
  • 批准号:
    2232813
  • 财政年份:
    2023
  • 资助金额:
    $ 49.99万
  • 项目类别:
    Standard Grant
CICI: UCSS: Building a Community of Practice for Supporting Regulated Research
CICI:UCSS:建立支持监管研究的实践社区
  • 批准号:
    2409859
  • 财政年份:
    2023
  • 资助金额:
    $ 49.99万
  • 项目类别:
    Standard Grant
CICI: UCSS: Enhancing the Usability of Vulnerability Assessment Results for Open-Source Software Technologies in Scientific Cyberinfrastructure: A Deep Learning Perspective
CICI:UCSS:增强科学网络基础设施中开源软件技术漏洞评估结果的可用性:深度学习视角
  • 批准号:
    2319325
  • 财政年份:
    2023
  • 资助金额:
    $ 49.99万
  • 项目类别:
    Standard Grant
{{ showInfoDetail.title }}

作者:{{ showInfoDetail.author }}

知道了