Using a PTD to Strengthen Remote Authentication from an Untrusted Computer
Chin‐Ling Chen, Cheng‐Chi Lee, Neng-Chung Wang, Chao-Yung Hsu · 網際網路技術學刊 · 2012
Unsecured public terminals are problematic for use with Internet services that require security, especially those used by financial institutions. Malicious software and phishing attacks on unsecured computers can extract user credentials or other personal sensitive information and can be used for unauthorized access of user accounts. Although many systems utilize sophisticated one-time passwords or challenge-response techniques to counter these attacks, most proposed schemes are vulnerable to session hijacking. To address this problem, we propose a novel authentication protocol for remote authentication using personal trusted device (PTD) with fingerprint biometrics to protect shared secrets between users and servers. Moreover, our approach allows users to input sensitive information from a personal, trusted device to prevent malicious software attacks; and we facilitate a transaction phase to prevent session hijacking. We also use hashing functions to implement a robust authentication with a low computational cost.