Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...Mobile Secured Authentication Mobile Secured Authentication
Previous
 
Next
New Post
7/12/2007 9:00 PM
 
Mobile Secured Authentication
 
We are working on a new user registration, site access and authentication component utilizing SMS messaging to Mobile phones.
 
Rules based system but the basic flow is as follows:
 
#1: Login / Registration
 
Mobile Number
Enter your PIN : 
 
 
#2  Access  verification with Ajax Token
 
202-555-1212
***********  
 
Enter  Key   :
 
{timer}
Your site access key has been sent to your mobile phone:
Please reply to the SMS or enter key code for access
 
SMS Message
Key: SAMPLE
mysecuresite.com
IP: 192.168.1.1
07.07.12:13:52GST
Reply or enter Key code for access.
 
 
Benefit for this security method:
 
#1: Simple – less code and more secure
#2: Authentication transported in two parts across two separate networks (voice and data)
#3: No Bots – No captcha - No additional user clicks
#4: Privacy – No personal identification or email stored in system.
#5: End User gets a SMS notification and receipt per access.
#6: Pin prevents spam SMS
#7: Demographic control for site access: ie. country, area, provider etc.
#8: One time encryption key for session
#9: Mobil number can be used for license generation - acceptable use etc.
#10: SMS access to portal users


Cons:

#1: Limits site access to those with Mobile phones on supported networks.
#2: SMS messaging cost (Free to a few cents per login)
#3: SMS message delay for reply authentication (10 seconds) 
#4: No remember me.. autologin etc...  (This is for security)

We are looking for ideas and ways to defeat this new authentication scheme.  So far we are stumped as even a wire tap over the data and voice network will not be easy to defeat such system within a 5 minute period not to mention the key is limited to the specific IP.

- Flooding and Denial of Service attacks: - Watchdog / IP  Banning
- SMS Spoofing  - PIN with rules lockout
- Lost Pin - 24 hour delay before sending
- Session Interception - SSL or better SMS one time encryption key.

Applications are for financial portals - software downloads -  Mobile number can be integrated into the software key to track piracy and abuse.   Lots of applications for this rules based system.

Feedback please.
 
New Post
7/14/2007 2:06 PM
 

No takers?  Surely there must be some comments and ideas from the peanut gallery...

 
Previous
 
Next
HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...Mobile Secured Authentication Mobile Secured Authentication


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out