MPKIX: Towards More Accountable and Secure Internet Application Services via Mobile Networked Systems

Tian Xie,Sihan Wang,Xinyu Lei,Jingwen Shi,Guan-Hua Tu,Chi-Yu Li
DOI: https://doi.org/10.1109/tmc.2022.3141694
IF: 6.075
2022-01-01
IEEE Transactions on Mobile Computing
Abstract:Nowadays, both Internet Application Service (IAS) providers and users face various security threats and legal issues. Due to the lack of reliable user information verification mechanisms, adversaries can abuse IASs to launch various cyberattacks, such as misinformation distributing and phishing, by using fake user accounts. IAS providers may thus inadvertently offer inappropriate content to restricted users, thereby suffering a serious risk of prosecution under local or international laws. Also, IAS users may suffer from nefarious ID theft attacks. In this paper, we proposed a novel security framework, ${{\sf MPKIX}}$MPKIX, designated as Mobile-assisted PKIX (Public-Key Infrastructure X.509). ${{\sf MPKIX}}$MPKIX secures both IAS providers and users by leveraging the broadly used PKIX services and mobile networked systems. It not only provides IAS providers with a reliable user verification mechanism while simultaneously enabling cross-IAS user privacy protection, but also largely mitigates the possibility of ID theft attacks and benefits other involved parties, such as cellular network operators and PKIX service providers. We further conduct a security analysis of ${{\sf MPKIX}}$MPKIX and implement an ${{\sf MPKIX}}$MPKIX prototype. The evaluation results based on the prototype confirm the effectiveness and efficiency of ${{\sf MPKIX}}$MPKIX with low overhead.
computer science, information systems,telecommunications
What problem does this paper attempt to address?