Sesame: a secure and convenient mobile solution for passwords

Mehrdad Aliasgari, Nick Sabol, Ashutosh Sharma
{"title":"Sesame: a secure and convenient mobile solution for passwords","authors":"Mehrdad Aliasgari, Nick Sabol, Ashutosh Sharma","doi":"10.1109/MOBISECSERV.2015.7072879","DOIUrl":null,"url":null,"abstract":"Passwords are the main and most common method of remote authentication. However, they have their own frustrating challenges. Users tend to forget passwords that are chosen to be hard to guess. Password managers are an approach to keeping our passwords safe. However, they mainly rely on one master password to secure all of our passwords. If this master password is compromised then all other passwords can be recovered. In this work, we introduce Sesame: a secure yet convenient mobile-based, voice-activated password manager. It combines all different methods of user authentication to create a more robust digital vault for personal data. Each password is encrypted with a new fresh key on the user's mobile device for maximum security. The keys are stored in our servers in a protected format. The user has the option of backing up the encrypted passwords in any cloud service. To view a password, the user only needs to utter the name of a web service, and speaker and speech recognition are applied for authentication. Only the key for that service is sent to the mobile application and the password is decrypted and displayed. The biggest advantage of Sesame is that the user need not assume any trust to neither our servers nor any cloud storage. Also, there is no need to enter a master password every time since speaker recognition is used. However, as an alternative to voice, users can view their passwords using a master password in case voice is not available. We provide a brief analysis of the security of our solution that has been implemented on Android platform and freely available on Google Play. Sesame is an ideal and practical solution for mobile password managers.","PeriodicalId":164383,"journal":{"name":"2015 First Conference on Mobile and Secure Services (MOBISECSERV)","volume":"118 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2015-04-02","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2015 First Conference on Mobile and Secure Services (MOBISECSERV)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/MOBISECSERV.2015.7072879","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2

Abstract

Passwords are the main and most common method of remote authentication. However, they have their own frustrating challenges. Users tend to forget passwords that are chosen to be hard to guess. Password managers are an approach to keeping our passwords safe. However, they mainly rely on one master password to secure all of our passwords. If this master password is compromised then all other passwords can be recovered. In this work, we introduce Sesame: a secure yet convenient mobile-based, voice-activated password manager. It combines all different methods of user authentication to create a more robust digital vault for personal data. Each password is encrypted with a new fresh key on the user's mobile device for maximum security. The keys are stored in our servers in a protected format. The user has the option of backing up the encrypted passwords in any cloud service. To view a password, the user only needs to utter the name of a web service, and speaker and speech recognition are applied for authentication. Only the key for that service is sent to the mobile application and the password is decrypted and displayed. The biggest advantage of Sesame is that the user need not assume any trust to neither our servers nor any cloud storage. Also, there is no need to enter a master password every time since speaker recognition is used. However, as an alternative to voice, users can view their passwords using a master password in case voice is not available. We provide a brief analysis of the security of our solution that has been implemented on Android platform and freely available on Google Play. Sesame is an ideal and practical solution for mobile password managers.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
芝麻:安全便捷的移动密码解决方案
密码是远程认证的主要和最常用的方法。然而,他们也有自己令人沮丧的挑战。用户往往会忘记那些难以猜到的密码。密码管理器是一种保护密码安全的方法。然而,他们主要依靠一个主密码来保护我们所有的密码。如果这个主密码被泄露,那么所有其他密码都可以恢复。在这项工作中,我们介绍了芝麻:一个安全而方便的基于手机的语音激活密码管理器。它结合了所有不同的用户身份验证方法,为个人数据创建了一个更强大的数字保险库。每个密码都在用户的移动设备上用一个新的密钥加密,以达到最大的安全性。密钥以受保护的格式存储在我们的服务器中。用户可以选择在任何云服务中备份加密密码。查看密码时,用户只需要说出web服务的名称,就可以进行免提认证和语音识别。只有该服务的密钥被发送到移动应用程序,密码被解密并显示。Sesame最大的优势是用户无需对我们的服务器和任何云存储承担任何信任。此外,由于使用了说话人识别,因此每次都不需要输入主密码。但是,作为语音的替代方案,用户可以在语音不可用的情况下使用主密码查看他们的密码。我们对我们的解决方案的安全性进行了简要分析,该解决方案已在Android平台上实施,并可在Google Play上免费使用。芝麻是一个理想的和实用的解决方案,移动密码管理器。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Over-the-internet: efficient remote content management for secure elements in mobile devices Performance variation in host-based card emulation compared to a hardware security element An authentication architecture for cloud-based firewalling service Leveraging COBIT5 in NFC-based payment technology: challenges and opportunities for security risk mitigation and audit Two-factor authentication for android host card emulated contactless cards
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1