Towards securing client-server connections against man-in-the-middle attacks

Mihai Ordean, Mircea Giurgiu · 2012

This paper presents the design concept for an authentication string that makes use of the server's public key and provides client's authenticity through its password without the need of a client side certificate or a second channel. Successful strategies for preventing man-in-the middle attacks are currently relying either on two channel/two factor authentication or two-way encryption. Both these strategies have their downsides, the first one requires users to carry a physical device for authentication and the second requires all the devices that connect to the server have encryption certificates.

Read the paper · More papers on PaperTik