Authors:
Daniel V. Bailey
1
;
John Brainard
1
;
Sebastian Rohde
2
and
Christof Paar
2
Affiliations:
1
RSA, the Security Division of EMC, United States
;
2
Ruhr-Universität Bochum, Germany
Keyword(s):
User authentication, Online banking, Wi-Fi.
Related
Ontology
Subjects/Areas/Topics:
Access Control
;
Data Engineering
;
Databases and Data Security
;
Identification, Authentication and Non-Repudiation
;
Information and Systems Security
;
Internet Technology
;
Web Information Systems and Technologies
Abstract:
We present a design for a Wi-Fi user-authentication token that tunnels data through the SSID field, packet timing, and packet length. Previous attempts to build an online-banking transaction-signing token have been only moderately successful, due in large part to usability problems. Average consumers, especially in the United States, are simply unwilling to transcribe strings of digits from PC to token and back again. In a departure from previous work, our token communicates using point-to-point side-channels in Wi-Fi that allow two devices to directly exchange messages – even if one is also connected to an access point. The result is a token that can authenticate transactions using only one touch by the user. The increased usability means more transactions can be authenticated, reducing fraud and driving more banking business online.