Shoulder-surfing, phishing and keylogging are widely used by attackers to obtain users' sensitive credentials. In this paper, we propose a framework to strengthen password authentication using mobile devices and browser extensions. This approach provides a relatively high resilience against shoulder-surfing, phishing and keylogging attacks while requires no change on the server side. A prototype implementation of the proposed approach and its security analysis are also provided.
Published in:
Signal Processing and Information Technology (ISSPIT), 2010 IEEE International Symposium on
Date of Conference: 15-18 Dec. 2010