arrow
返回

Formal modelling and verifying eIDAS multi-factor authentication with interface-based threat analysis

delete2026-01-01
delete0
delete
OA
AI
P
Paier, Matteo
V
Van Eeden, Roberto L. G.
M
Marino Miculan *
DOI:10.1007/s10270-026-01375-9delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
本文介绍了一种用于形式化建模和验证eIDAS数字身份卡中使用的多因素认证(MFA)方案的方法。我们的方法采用基于接口的威胁模型,系统分析潜在漏洞,并根据不同攻击者能力列举一系列威胁场景。我们以意大利电子身份证(CIE)作为实际案例研究,展示了为这些场景自动生成ProVerif模型的过程。我们的分析揭示了若干安全弱点;值得注意的是,在某些情况下,仅拥有Level 1(即单因素)凭证的攻击者可以在不破坏任何通信接口的情况下实现Level 2多因素认证。为缓解这些漏洞,我们提出了对协议的微小修改。此外,在Level 3层面,我们的分析显示,依赖CieID智能手机应用程序的认证方案相比使用带智能卡读卡器的PC的方法具有更广泛的攻击面。本文提出的基于接口的建模与分析方法为其他eIDAS数字身份卡的安全评估提供了一个有价值的框架。
Keyword:
Formal modelling, specification, and design
Multi-factor authentication
Security, privacy, and trust
Threat models

期刊

S
Software and Systems Modeling
IF:
3.2
论文数:
61
被引数:
1.9K

机构

U
university of udine
学者数:
1.3K
论文数: 546
被引数: 0
引用论文

引用论文

A Practical Implementation of the Timing Attack
err2000-01-01
err0
PREAI
errJean-François Dhem; François Koeune; Philippe-Alexandre Leroux; Patrick Mestré; Jean-Jacques Quisquater; Jean-Louis Willems
err分享
err收藏
Formal analysis of SAML 2.0 web browser single sign-on
err2008-10-27
err0
PREAI
errAlessandro Armando; Roberto Carbone; Luca Compagna; Jorge Cuellar; Llanos Tobarra
err分享
err收藏
err分享
err收藏
SS7 Vulnerabilities-A Survey and Implementation of Machine Learning vs Rule Based Filtering for Detection of SS7 Network Attacks
err2020-01-01
err158
PREAI
errUllah, Kaleem; Rashid, Imran; Afzal, Hammad; Iqbal, Mian Muhammad Waseem; Bangash, Yawar Abbas; Abbas, Haider
err分享
err收藏
The eIDAS Regulation: A Survey of Technological Trends for European Electronic Identity Schemes
err2022-12-10
err0
errOAAI
errAmir Sharif; Matteo Ranzi; Roberto Carbone; Giada Sciarretta; Francesco Antonio Marino; Silvio Ranise
err分享
err收藏
学者 查看更多内容