Back to Search Start Over

Issues of identity verification of typical applications over mobile terminal platform

Authors :
ZHANG Xiaolin, GU Dawu
ZHANG Chi
Source :
网络与信息安全学报, Vol 6, Iss 6, Pp 137-151 (2020)
Publication Year :
2020
Publisher :
POSTS&TELECOM PRESS Co., LTD, 2020.

Abstract

Recent studies have shown that attacks against USIM card are increasing, and an attacker can use the cloned USIM card to bypass the identity verification process in some applications and thereby get the unauthorized access. Considering the USIM card being cloned easily even under 5G network, the identity verification process of the popular mobile applications over mobile platform was analyzed. The application behaviors were profiled while users were logging in, resetting password, and performing sensitive operations, thereby the tree model of application authentication was summarized. On this basis, 58 popular applications in 7 categories were tested including social communication, healthcare, etc. It found that 29 of them only need SMS verification codes to get authenticated and obtain permissions. To address this issue, two-step authentication was suggested and USIM anti-counterfeiting was applied to assist the authentication process.

Details

Language :
English, Chinese
ISSN :
2096109x and 2096109X
Volume :
6
Issue :
6
Database :
Directory of Open Access Journals
Journal :
网络与信息安全学报
Publication Type :
Academic Journal
Accession number :
edsdoj.1b47423b3fe4b3b81041fbf0be425d1
Document Type :
article
Full Text :
https://doi.org/10.11959/j.issn.2096-109x.2020081