SafeKeeper: Protecting Web Passwords using Trusted Execution Environments

Klaudia Krawiecka, Arseny Kurnikov, Andrew Paverd, Mohmmad Mannan, N. Asokan

Tutkimustuotos: Artikkeli kirjassa/konferenssijulkaisussaConference article in proceedingsScientificvertaisarvioitu

314 Lataukset (Pure)

Abstrakti

Passwords are by far the most widely-used mechanism for authenticating users on the web, out-performing all competing solutions in terms of deployability (e.g. cost and compatibility). However, two critical security concerns are phishing and theft of password databases. These are exacerbated by users» tendency to reuse passwords across different services. Current solutions typically address only one of the two concerns, and do not protect passwords against rogue servers. Furthermore, they do not provide any verifiable evidence of their (server-side) adoption to users, and they face deployability challenges in terms of ease-of-use for end users, and/or costs for service providers. We present SafeKeeper, a novel and comprehensive solution to ensure secrecy of passwords in web authentication systems. Unlike previous approaches, SafeKeeper protects users» passwords against very strong adversaries, including external phishers as well as corrupted (rogue) servers. It is relatively inexpensive to deploy as it (i) uses widely available hardware-based trusted execution environments like Intel SGX, (ii) requires only minimal changes for integration into popular web platforms like WordPress, and (iii) imposes negligible performance overhead. We discuss several challenges in designing and implementing such a system, and how we overcome them. Via an 86-participant user study, systematic analysis and experiments, we show the usability, security and deployability of SafeKeeper, which is available as open-source.
AlkuperäiskieliEnglanti
OtsikkoWWW '18 : Proceedings of the 2018 World Wide Web Conference
KustantajaACM
Sivut349-358
Sivumäärä10
ISBN (elektroninen)978-1-4503-5639-8
DOI - pysyväislinkit
TilaJulkaistu - 23 huhtik. 2018
OKM-julkaisutyyppiA4 Artikkeli konferenssijulkaisussa
TapahtumaINTERNATIONAL WORLD WIDE WEB CONFERENCE - Lyon, Ranska
Kesto: 23 huhtik. 201827 huhtik. 2018
https://www2018.thewebconf.org

Conference

ConferenceINTERNATIONAL WORLD WIDE WEB CONFERENCE
LyhennettäWWW
Maa/AlueRanska
KaupunkiLyon
Ajanjakso23/04/201827/04/2018
www-osoite

Sormenjälki

Sukella tutkimusaiheisiin 'SafeKeeper: Protecting Web Passwords using Trusted Execution Environments'. Ne muodostavat yhdessä ainutlaatuisen sormenjäljen.
  • CloSer: Cloud-assisted Security Services (CloSer)

    Asokan, N. (Vastuullinen johtaja), Nyman, T. (Projektin jäsen), Kurnikov, A. (Projektin jäsen), Vieitez Parra, R. (Projektin jäsen), Reuter, M. (Projektin jäsen), Valiev, A. (Projektin jäsen), Tamrakar, S. (Projektin jäsen), Paverd, A. (Projektin jäsen), Roshan Kokabha, S. (Projektin jäsen), Liljestrand, H. (Projektin jäsen), Pajola, L. (Projektin jäsen), Rieger, P. (Projektin jäsen) & Liu, J. (Projektin jäsen)

    01/09/201631/08/2018

    Projekti: Business Finland: Other research funding

Siteeraa tätä