SMS-Based One-Time Passwords: Attacks and Defense - (Short Paper).

Collin Mulliner, Ravishankar Borgaonkar, Patrick Stewin, Jean‐Pierre Seifert · 2013

Abstract. SMS-based One-Time Passwords (SMS OTP) were intro-duced to counter phishing and other attacks against Internet services such as online banking. Today, SMS OTPs are commonly used for au-thentication and authorization for many different applications. Recently, SMS OTPs have come under heavy attack, especially by smartphone Trojans. In this paper, we analyze the security architecture of SMS OTP systems and study attacks that pose a threat to Internet-based authen-tication and authorization services. We determined that the two founda-tions SMS OTP is built on, cellular networks and mobile handsets, were completely different at the time when SMS OTP was designed and intro-duced. Throughout this work, we show why SMS OTP systems cannot be considered secure anymore. Based on our findings, we propose mech-anisms to secure SMS OTPs against common attacks and specifically against smartphone Trojans.

Read the paper · More papers on PaperTik