FIDO2 With Two Displays-Or How to Protect Security-Critical Web Transactions Against Malware Attacks
Timon Hackenjos, Benedikt Wagner, Julian Herr, Jochen Rill, Marek, Wehmer, Niklas Goerke, Ingmar Baumgart

TL;DR
This paper introduces FIDO2D, a novel web authentication scheme that enhances security by enabling transaction authentication and resisting malware, addressing limitations of existing two-factor authentication methods.
Contribution
It proposes a new paradigm for web authentication that ensures one-out-of-two security and transaction protection, and presents FIDO2D based on this paradigm with security proof.
Findings
FIDO2D protects transactions even if one factor is compromised.
Existing schemes do not achieve one-out-of-two security.
FIDO2D is proven secure using Tamarin.
Abstract
With the rise of attacks on online accounts in the past years, more and more services offer two-factor authentication for their users. Having factors out of two of the three categories something you know, something you have and something you are should ensure that an attacker cannot compromise two of them at once. Thus, an adversary should not be able to maliciously interact with one's account. However, this is only true if one considers a weak adversary. In particular, since most current solutions only authenticate a session and not individual transactions, they are noneffective if one's device is infected with malware. For online banking, the banking industry has long since identified the need for authenticating transactions. However, specifications of such authentication schemes are not public and implementation details vary wildly from bank to bank with most still being unable to…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsUser Authentication and Security Systems · Spam and Phishing Detection · Internet Traffic Analysis and Secure E-voting
