Mobile Browser as a Second Factor for Web Authentication

Zhi Guan,Hu Xiong,Suke Li,Zhong Chen
DOI: https://doi.org/10.1109/ISPA.2011.63
2011-01-01
Abstract:People's increasingly relying on web applications to manage their digital assets makes web authentication a critical security issue. As most websites today still authenticate a user with only username and password, the authentication credentials can be easily compromised in a vulnerable browsing environment without the owner's notice. Considering the browsing in mobile devices is more secure than personal computers, in this paper we explore the One-Time Password web application running inside mobile browsers as a second authentication factor for high value websites in hostile browsing environments. We discuss the security and efficiency of this authentication method from both theory and practice. An implementation with performance evaluation is also provided to prove our concept.
What problem does this paper attempt to address?