Context-Aware Phishing-Resistant Authentication for Federated Identity in Internet of Things Platforms

Jian-ping Yang, Binxing Fang, Hui Dong Lu, Zhihong Tian · IEEE Internet of Things Journal · 2024

The Internet of Things (IoT) has seen widespread adoption across various industries, enabling cross-domain collaboration among devices. As IoT platforms that allows users to manage and control these IoT devices become more prevalent, the security of IoT platforms has come under increasing scrutiny. Cryptographic authentication (CA) has long been central to authentication but poses significant security risks, such as account takeovers due to credential disclosure. Unfortunately, CA remains the most popular authentication scheme for IoT platforms, making them vulnerable to phishing attacks. Current enhancement methods, including challenge-response protocols and multifactor authentication, are still susceptible to phishing and face usability issues, particularly in cross-domain collaboration systems where seamless access is crucial. This article introduces Context-Auth, a context-aware authentication scheme designed to defend against phishing attacks without requiring tamper-resistant hardware. By incorporating contextual features of authentication and access behaviors into access credentials, Context-Auth detects inconsistencies and strengthens security. Our scheme addresses cross-domain verification challenges in federated identity scenarios, ensuring high usability across various devices without additional requirement from users. We conducted comprehensive evaluations and security analyses to ensure that Context-Auth remains secure against potential threats. The experimental results demonstrate that Context-Auth effectively defends against phishing attacks launched by real-world phishing kits.

Read the paper · More papers on PaperTik