showSidebars ==
showTitleBreadcrumbs == 1
node.field_disable_title_breadcrumbs.value ==

Pre-Conference Talk by LIU Ximing | Typing-Proof: Usable, Secure and Low-Cost Two-Factor Authentication Based on Keystroke Timings

Please click here if you are unable to view this page.

 

Typing-Proof: Usable, Secure and Low-Cost Two-Factor Authentication Based on Keystroke Timings

Speaker (s):

LIU Ximing

PhD Candidate

School of Information Systems

Singapore Management University

Date:


Time:


Venue:

 

November 27, 2018, Tuesday


2:00pm - 2:30pm


Meeting Room 4.4, Level 4

School of Information Systems

Singapore Management University

80 Stamford Road

Singapore 178902

We look forward to seeing you at this research seminar.

About the Talk

Two-factor authentication (2FA) systems provide another layer of protection to users' accounts beyond password. Traditional hardware token based 2FA and software token based 2FA are not burdenless to users since they require users to read, remember, and type a one-time code in the process, and incur high costs in deployments or operations. Recent 2FA mechanisms such as Sound-Proof, reduce or eliminate users' interactions for the proof of the second factor; however, they are not designed to be used in certain settings (e.g., quiet environments or PCs without built-in microphones), and they are not secure in the presence of certain attacks (e.g., sound-danger attack and co-located attack).

To address these problems, we propose Typing-Proof, a usable, secure and low-cost two-factor authentication mechanism. Typing-Proof is similar to software token based 2FA in a sense that it uses password as the first factor and uses a registered phone to prove the second factor. During the second-factor authentication procedure, it requires a user to type any random code on a login computer and authenticates the user by comparing the keystroke timing sequence of the random code recorded by the login computer with the sounds of typing random code recorded by the user's registered phone. Typing-Proof can be reliably used in any settings and requires zero user-phone interaction in the most cases. It is practically secure and immune to the existing attacks to recent 2FA mechanisms. In addition, Typing-Proof enables significant cost savings for both service providers and users.

This a pre-conference talk for Annual Computer Security Applications Conference (ACSAC 2018).

About the Speaker

LIU Ximing is a PhD candidate in Cybersecurity at School of Information Systems, Singapore Management University. He is advised by Associate Professor Yingjiu Li and AXA Chair Professor Robert H. Deng. In his PhD study, he focuses on user authentication and side-channel attacks.