محور البحث 02
المصادقة متعددة العوامل (MFA) والثنائية (2FA)
تحليل أمن وسائل العامل الثاني وتجربة استخدامها، ولا سيما المصادقة بالإشعارات الفورية.
السؤال البحثي
متى تضيف MFA حماية حقيقية، ومتى تفتح طريقة التفاعل نفسها بابًا لهجمات جديدة؟
يركّز هذا المحور على المصادقة بالإشعارات الفورية (Push Authentication)، وهجمات الإغراق بالإشعارات، وتزامن محاولات الدخول، وأساليب المقارنة والتأكيد (Compare-and-Confirm). ويبحث في كيفية تصميم خطوة تحقق ثانية تساعد المستخدم على اتخاذ قرار أمني صحيح.
من الأدبيات
منشورات مرتبطة بالمحور
أبحاث منشورة ترتبط مباشرة بالأسئلة التي يتناولها هذا المحور.
An In-Depth Analysis of Password Managers and Two-Factor Authentication Tools
Mohammed Jubur, Prakash Shrestha, Nitesh Saxena
ACM Computing Surveys
Usability and Security Analysis of the Compare-and-Confirm Method in Mobile Push-Based Two-Factor Authentication
Mohammed Jubur, Nitesh Saxena, Faheem A. Reegu
IEEE Transactions on Mobile Computing
Breaking Mobile Notification-Based Authentication with Concurrent Attacks Outside of Mobile Devices
Ahmed Tanvir Mahdad, Mohammed Jubur, Nitesh Saxena
ACM MobiCom
Bypassing Push-Based Second Factor and Passwordless Authentication with Human-Indistinguishable Notifications
Mohammed Jubur, Prakash Shrestha, Nitesh Saxena, Jay Prakash
ACM AsiaCCS
Countering Concurrent Login Attacks in Just Tap Push-Based Authentication: A Redesign and Usability Evaluations
Jay Prakash, Clarice C. Q. Yu, Tanvi R. Thombre, Andrei Bytes, Mohammed Jubur, Nitesh Saxena, Lucienne Blessing, Jianying Zhou, Tony Q. S. Quek
IEEE EuroS&P
Two-Factor Password-Authenticated Key Exchange with End-to-End Security
Stanislaw Jarecki, Mohammed Jubur, Hugo Krawczyk, Maliheh Shirvanian, Nitesh Saxena
ACM Transactions on Privacy and Security
اقرأ وتعرّف
مقالات تشرح هذا المحور
محتوى عربي محرر يربط المفاهيم التقنية بالاستخدام اليومي.
لماذا نستخدم SMS OTP؟ ومتى نحتاج أجهزة Hardware Token؟
رحلة رمز SMS من الخادم إلى الهاتف، ومخاطر القناة والتصيّد، ثم مقارنة ذلك بأجهزة TOTP وHOTP المستقلة.
6 دقائقالمصادقة الثنائية (2FA): طبقة إضافية لا تعمل بالطريقة نفسها دائمًا
شرح عوامل المصادقة وطرق 2FA الشائعة، مع توضيح الفرق بين الحماية الإضافية والمقاومة الحقيقية للتصيّد.