Abstract

This paper describes a new mobile authentication method which is based on an Open ID Connect standard and subscriber identity module card. The proposed solution enables users to access websites, services and applications without the need to remember passwords, responses or support of any equipment. The proposed method is evaluated from the users’ perspective as well as from the security viewpoint. Moreover, we compare it with the two most popular existing authentication schemes i.e. static passwords and SMS OTP (one time password). In order to evaluate user’s view on various authentication methods a questionnaire was prepared and distributed among 40 participants. Obtained results revealed that the new authentication scheme yielded better results than the existing methods. Finally, we also performed a security analysis with respect to all abovementioned authentication solutions to assess whether there are any major risks related to the proposed method.

Highlights

  • Along with the dynamic development and utilization of the self-care services, such as banking, e-commerce, healthcare, or e-government, there has been an increasing demand to properly authenticate users in a secure manner

  • Considering the above, the main contribution of this paper is to demonstrate an innovative authentication solution that focuses on the usage that is at the same time comfortable and secure

  • Evidence presented in [12], which is based on the research into facial and fingerprint mobile authentication applications, shows that such mobile applications are vulnerable to several attacks, which poses a serious threat to the overall system security and user privacy

Read more

Summary

Introduction

Along with the dynamic development and utilization of the self-care services, such as banking, e-commerce, healthcare, or e-government, there has been an increasing demand to properly authenticate users in a secure manner. Considering above, the aim of this paper is to evaluate the proposed mobile authentication method from the user perspective as well as from the point of view of security. We focus both on user’s comfort and security. Considering the above, the main contribution of this paper is to demonstrate an innovative authentication solution that focuses on the usage that is at the same time comfortable and secure This new authentication method was designed, developed and evaluated in comparison with other most common methods.

Related work
System architecture
Details of the experimental methodology
Method
Results of the experimental evaluation concerning convenience
Duration of the login process
Security analysis
Users’ perception
Network
Mobile environments
Findings
Conclusion and future work
Full Text
Published version (Free)

Talk to us

Join us for a 30 min session where you can share your feedback and ask us any queries you have

Schedule a call