Mostrar el registro sencillo del ítem

dc.contributor.authorMarforio, Claudio
dc.contributor.authorKarapanos, Nikolaos
dc.contributor.authorSoriente, Claudio
dc.contributor.authorKostiainen, Kari
dc.contributor.authorCapkun, Srdjan
dc.date.accessioned2025-01-10T16:59:47Z
dc.date.available2025-01-10T16:59:47Z
dc.date.issued2014
dc.identifier.citationMarforio, C., Karapanos, N., Soriente, C., Kostiainen, K., & Capkun, S. (2014, February). Smartphones as Practical and Secure Location Verification Tokens for Payments. In NDSS (Vol. 14, pp. 23-26). https://doi.org/10.14722/ndss.2014.23165es
dc.identifier.otherhttps://www.ndss-symposium.org/ndss2014/ndss-2014-programme/smartphones-practical-and-secure-location-verification-tokens-payments/es
dc.identifier.urihttp://hdl.handle.net/20.500.12020/1458
dc.description.abstractWe propose a novel location-based second-factor authentication solution for modern smartphones. We demonstrate our solution in the context of point of sale transactions and show how it can be effectively used for the detection of fraudulent transactions caused by card theft or counterfeiting. Our scheme makes use of Trusted Execution Environments (TEEs), such as ARM TrustZone, commonly available on modern smartphones, and resists strong attackers, even those capable of compromising the victim phone applications and OS. It does not require any changes in the user behavior at the point of sale or to the deployed terminals. In particular, we show that practical deployment of smartphone-based second-factor authentication requires a secure enrollment phase that binds the user to his smartphone TEE and allows convenient device migration. We then propose two novel enrollment schemes that resist targeted attacks and provide easy migration. We implement our solution within available platforms and show that it is indeed realizable, can be deployed with small software changes, and does not hinder user experience.es
dc.language.isoenes
dc.publisherInternet Societyes
dc.rightsAttribution-NonCommercial-NoDerivatives 4.0 Internacional*
dc.rights.urihttp://creativecommons.org/licenses/by-nc-nd/4.0/*
dc.titleSmartphones as Practical and Secure Location Verification Tokens for Paymentses
dc.typeconferenceObjectes
dc.identifier.conferenceObjectNetwork and Distributed System Security Symposium, 23-26 de febrero 2014, San Diego EEUUes
dc.identifier.doihttps://doi.org/10.14722/ndss.2014.23165
dc.rights.accessRightsopenAccesses
dc.subject.areaIngenieríases
dc.subject.keywordTrusted Execution Environmentses
dc.subject.keywordMobile Paymentses
dc.subject.keywordSecurityes
dc.subject.unesco33 Ciencias Tecnológicases


Ficheros en el ítem

Este ítem aparece en la(s) siguiente(s) colección(ones)

Mostrar el registro sencillo del ítem

Attribution-NonCommercial-NoDerivatives 4.0 Internacional
Excepto si se señala otra cosa, la licencia del ítem se describe como Attribution-NonCommercial-NoDerivatives 4.0 Internacional