Title
SIMulation: Demystifying (Insecure) Cellular Network based One-Tap Authentication Services
Abstract
A recently emerged cellular network based One-Tap Authentication (OTAuth) scheme allows app users to quickly sign up or log in to their accounts conveniently: Mobile Network Operator (MNO) provided tokens instead of user passwords are used as identity credentials. After conducting a first in-depth security analysis, however, we have revealed several fundamental design flaws among popular OTAuth services, which allow an adversary to easily (1) perform unauthorized login and register new accounts as the victim, (2) illegally obtain identities of victims, and (3) interfere OTAuth services of legitimate apps. To further evaluate the impact of our identified issues, we propose a pipeline that integrates both static and dynamic analysis. We examined 1,025/894 Android/iOS apps, each app holding more than 100 million installations. We confirmed 396/398 Android/iOS apps are affected. Our research systematically reveals the threats against OTAuth services. Finally, we provide suggestions on how to mitigate these threats accordingly.
Year
DOI
Venue
2022
10.1109/DSN53405.2022.00059
2022 52nd Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN)
Keywords
DocType
ISSN
mobile security,mobile network operator,cellular network,malware,SIM card based authentication
Conference
1530-0889
ISBN
Citations 
PageRank 
978-1-6654-1694-8
0
0.34
References 
Authors
8
6
Name
Order
Citations
PageRank
Ziyi Zhou100.34
Xing Han200.34
Zeyuan Chen300.34
Yuhong Nan400.34
Juanru Li517924.07
Dawu Gu6644103.50