Enhanced Password Security on Mobile Devices

dc.contributor.advisor

Cox, Landon P

dc.contributor.author

Liu, Dongtao

dc.date.accessioned

2013-12-16T20:13:59Z

dc.date.available

2013-12-16T20:13:59Z

dc.date.issued

2013

dc.department

Computer Science

dc.description.abstract

Sleek and powerful touchscreen devices with continuous access to high-bandwidth wireless data networks have transformed mobile into a first-class development platform. Many applications (i.e., "apps") written for these platforms rely on remote services such as Dropbox, Facebook, and Twitter, and require users to provide one or more passwords upon installation. Unfortunately, today's mobile platforms provide no protection for users' passwords, even as mobile devices have become attractive targets for password-stealing malware and other phishing attacks.

This dissertation explores the feasibility of providing strong protections for passwords input on mobile devices without requiring large changes to existing apps.

We propose two approaches to secure password entry on mobile devices: ScreenPass and VeriUI. ScreenPass is integrated with a device's operating system and continuously monitors the device's screen to prevent malicious apps from spoofing the system's trusted software keyboard. The trusted keyboard ensures that ScreenPass always knows when a password is input, which allows it to prevent apps from sending password data to the untrusted servers. VeriUI relies on trusted hardware to isolate password handling from a device's operating system and apps. This approach allows VeriUI to prove to remote services that a relatively small and well-known code base directly handled a user's password data.

dc.identifier.uri

https://hdl.handle.net/10161/8239

dc.subject

Computer science

dc.subject

Mobile computing

dc.subject

Password

dc.subject

Security

dc.subject

Trusted UI

dc.title

Enhanced Password Security on Mobile Devices

dc.type

Dissertation

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
Liu_duke_0066D_12198.pdf
Size:
1.18 MB
Format:
Adobe Portable Document Format

Collections