Detail publikace

Detecting and Preventing Credential Misuse in OTP-Based Two and Half Factor Authentication Toward Centralized Services Utilizing Blockchain-Based Identity Management

DRGA, J. HOMOLIAK, I. VANČO, J. PEREŠÍNI, M. HANÁČEK, P. VASILAKOS, A.

Originální název

Detecting and Preventing Credential Misuse in OTP-Based Two and Half Factor Authentication Toward Centralized Services Utilizing Blockchain-Based Identity Management

Typ

článek ve sborníku ve WoS nebo Scopus

Jazyk

angličtina

Originální abstrakt

This paper focuses on the problem of detection and prevention of stolen and misused secrets (such as private keys) for authentication toward centralized services. We propose a solution for this problem, based on SmartOTPs, the two-factor authentication scheme against the blockchain, which is intended for smart contract wallets and utilizes one-time passwords (OTPs). We modify SmartOTPs for our purposes and utilize them in the setting of two-and-a-half-factor authentication against a centralized service provider. Out of two and a half factors of our solution, the first factor stands for the private key, and the second and a half factor stands for OTPs and their precursors (a.k.a., pre-images), where OTPs are obtained from the precursors by cryptoaraphically secure hashing. We describe the protocol for bootstrapping our approach as well as the authentication procedure. In the case of stolen creden-tials from the client, we show that our solution enables the user to immediately detect it and proceed to re-initialization with fresh credentials. We utilize blockchain-based identity management and decentralized identities of users to simplify the overhead of the registration process and reinitialization.

Klíčová slova

   - Centers For Services,    - Identity Management,    - Blockchain-based Identity Management,    - Privacy,    - Service Providers,    - Secret Key,    - User Identification,    - Smart Contracts,    - Authentication Scheme,    - Mnemonic,    - Types Of Attacks,    - Public Key,    - Malware,    - Authentication Process,    - Merkle Tree

Autoři

DRGA, J.; HOMOLIAK, I.; VANČO, J.; PEREŠÍNI, M.; HANÁČEK, P.; VASILAKOS, A.

Vydáno

22. 5. 2023

Nakladatel

Institute of Electrical and Electronics Engineers

Místo

Dubai

ISBN

979-8-3503-1019-1

Kniha

2023 IEEE International Conference on Blockchain and Cryptocurrency (ICBC)

Strany od

1

Strany do

4

Strany počet

4

BibTex

@inproceedings{BUT185114,
  author="Jozef {Drga} and Ivan {Homoliak} and Juraj {Vančo} and Martin {Perešíni} and Petr {Hanáček} and Athanasios {Vasilakos}",
  title="Detecting and Preventing Credential Misuse in OTP-Based Two and Half Factor Authentication Toward Centralized Services Utilizing Blockchain-Based Identity Management",
  booktitle="2023 IEEE International Conference on Blockchain and Cryptocurrency (ICBC)",
  year="2023",
  pages="1--4",
  publisher="Institute of Electrical and Electronics Engineers",
  address="Dubai",
  doi="10.1109/ICBC56567.2023.10174997",
  isbn="979-8-3503-1019-1"
}