A Two Factor Based Anti-Phishing Method in Open ID
Muhammad Asif, Muhammad Shahzad Sarfraz, Shahbaz Ahmed, Nitin Kumar Tripathi · 2013
With the exponential growth in web based applications, a typical user has to create a lot of usernames and passwords in order to use these services, while using these services user have to keep track of her credentials which in turns results in high probability of identity theft. A secure and reliable identity management system is required in this scenario. OpenID is a good solution to interact with these services through one identity. However, it is quite vulnerable to different kind of attacks including phishing. To tackle such kinds of attacks, we purpose and evaluate a two factor based anti-phishing method using password and personal identification number which is considered very difficult to break. Proposed protocol works by taking two credentials from the user instead of one i.e. user password and her PIN code for verification at server side. This two factor based protocol is difficult to break even in case a phisher succeeds to get control of the user page.The prototype system is built and tested against the phishing attacks and is found to be strong enough for protection against identity theft.