{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,25]],"date-time":"2026-02-25T17:11:26Z","timestamp":1772039486416,"version":"3.50.1"},"publisher-location":"Berlin, Heidelberg","reference-count":42,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"value":"9783662454718","type":"print"},{"value":"9783662454725","type":"electronic"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2014]]},"DOI":"10.1007\/978-3-662-45472-5_24","type":"book-chapter","created":{"date-parts":[[2014,11,14]],"date-time":"2014-11-14T16:31:39Z","timestamp":1415982699000},"page":"365-383","source":"Crossref","is-referenced-by-count":51,"title":["On the (In)Security of Mobile Two-Factor Authentication"],"prefix":"10.1007","author":[{"given":"Alexandra","family":"Dmitrienko","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Christopher","family":"Liebchen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Christian","family":"Rossow","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ahmad-Reza","family":"Sadeghi","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2014,11,9]]},"reference":[{"key":"24_CR1","unstructured":"Google Wallet. \n                      http:\/\/www.google.com\/wallet\/how-it-works\/index.html"},{"key":"24_CR2","unstructured":"National vulnerability database version 2.2. \n                      http:\/\/nvd.nist.gov\/"},{"key":"24_CR3","unstructured":"Cell phone virus tries leaping to PCs (2005). \n                      http:\/\/news.cnet.com\/Cell-phone-virus-tries-leaping-to-PCs\/2100-7349_3-5876664.html?tag=mncol;txt"},{"key":"24_CR4","unstructured":"The security risks of Free Public WiFi (2009). \n                      http:\/\/searchsecurity.techtarget.com.au\/news\/2240020802\/The-security-risks-of-Free-Public-WiFi"},{"key":"24_CR5","unstructured":"KARMA demo on the CBS early show (2010). \n                      http:\/\/blog.trailofbits.com\/2010\/07\/21\/karma-demo-on-the-cbs-early-show\/"},{"key":"24_CR6","unstructured":"New Spitmo banking Trojan attacks Android users (2011). \n                      http:\/\/www.securitynewsdaily.com\/1048-spitmo-banking-trojan-attacks-android-users.html"},{"key":"24_CR7","doi-asserted-by":"crossref","unstructured":"RSA breach leaks data for hacking securID tokens (2011). \n                      http:\/\/www.theregister.co.uk\/2011\/03\/18\/rsa_breach_leaks_securid_data\/","DOI":"10.1016\/S1353-4858(11)70056-3"},{"key":"24_CR8","unstructured":"MasterCard PAYPASS (2012). \n                      http:\/\/www.mastercard.us\/paypass.html#\/home\/"},{"key":"24_CR9","unstructured":"Raiffeisen PhotoTAN (2012). \n                      http:\/\/www.raiffeisen.ch\/web\/phototan"},{"key":"24_CR10","unstructured":"RSA SecurID software token cloning: a new how-to (2012). \n                      http:\/\/arstechnica.com\/security\/2012\/05\/rsa-securid-software-token-cloning-attack\/"},{"key":"24_CR11","doi-asserted-by":"crossref","unstructured":"Aloul, F., Zahidi, S., El-Hajj, W.: Two factor authentication using mobile phones. In: IEEE\/ACS Computer Systems and Applications, May 2009","DOI":"10.1109\/AICCSA.2009.5069395"},{"key":"24_CR12","first-page":"65","volume":"4","author":"F Aloul","year":"2009","unstructured":"Aloul, F., Zahidi, S., ElHajj, W.: Multi factor authentication using mobile phones. Int. J. Math. Comput. Sci. 4, 65\u201380 (2009)","journal-title":"Int. J. Math. Comput. Sci."},{"issue":"4","key":"24_CR13","first-page":"18","volume":"3","author":"T Alves","year":"2004","unstructured":"Alves, T., Felton, D.: TrustZone: integrated hardware and software security. Inf. Q. 3(4), 18\u201324 (2004)","journal-title":"Inf. Q."},{"key":"24_CR14","unstructured":"Azema, J., Fayad, G.: M-Shield mobile security technology: making wireless secure. \n                      http:\/\/focus.ti.com\/pdfs\/wtbu\/ti_mshield_whitepaper.pdf"},{"key":"24_CR15","unstructured":"Balfanz, D., Felten, E.W.: Hand-held computers can be better smart cards. In: USENIX Security Symposium - Volume 8. USENIX Association (1999)"},{"key":"24_CR16","unstructured":"Castillo, C., McAfee: Android banking Trojans target Italy and Thailand (2013). \n                      http:\/\/blogs.mcafee.com\/mcafee-labs\/android-banking-trojans-target-italy-and-thailand\/"},{"key":"24_CR17","unstructured":"Castillo, C., McAfee: Phishing attack replaces Android banking apps with malware (2013). \n                      http:\/\/blogs.mcafee.com\/mcafee-labs\/phishing-attack-replaces-android-banking-apps-with-malware"},{"key":"24_CR18","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"114","DOI":"10.1007\/3-540-45866-2_10","volume-title":"Pervasive Computing","author":"D Clarke","year":"2002","unstructured":"Clarke, D., Gassend, B., Kotwal, T., Burnside, M., van Dijk, M., Devadas, S., Rivest, R.L.: The untrusted computer problem and camera-based authentication. In: Mattern, F., Naghshineh, M. (eds.) PERVASIVE 2002. LNCS, vol. 2414, pp. 114\u2013124. Springer, Heidelberg (2002)"},{"key":"24_CR19","unstructured":"Cronto Limited: Commerzbank and Cronto launch secure online banking with photoTAN - World\u2019s first deployment of visual transaction signing mobile solution (2008). \n                      http:\/\/www.cronto.com\/download\/Cronto_Commerzbank_photoTAN.pdf"},{"key":"24_CR20","unstructured":"Cronto Limited. CorpBanca and Cronto secure online banking transactions with CrontoSign (2011). \n                      http:\/\/www.cronto.com\/corpbanca-cronto-secure-online-banking-transactions-crontosign.htm"},{"key":"24_CR21","unstructured":"Dmitrienko, A., Liebchen, C., Rossow, C., Sadeghi, A.-R.: On the (in)security of mobile two-factor authentication. Technical Report TUD-CS-2014-0029. CASED (2014). \n                      http:\/\/www.trust.informatik.tu-darmstadt.de\/fileadmin\/user_upload\/Group_TRUST\/PubsPDF\/TUD-CS-2014-0029.pdf"},{"key":"24_CR22","unstructured":"Enck, W., Gilbert, P., Chun, B.-G., Cox, L.P., Jung, J., McDaniel, P., Sheth, A.N.: TaintDroid: an information-flow tracking system for realtime privacy monitoring on smartphones. In: USENIX OSDI (2010)"},{"key":"24_CR23","unstructured":"Evers, J.: Virus makes leap from PC to PDA (2006). \n                      http:\/\/news.cnet.com\/2100-1029_3-6044457.html"},{"key":"24_CR24","unstructured":"Giesecke & Devrient: The Mobile Security Card offers increased security. \n                      http:\/\/www.gd-sfs.com\/the-mobile-security-card\/mobile-security-card-se-1--0\/"},{"key":"24_CR25","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"21","DOI":"10.1007\/978-3-540-85855-3_3","volume-title":"Security and Cryptography for Networks","author":"YI Jerschow","year":"2008","unstructured":"Jerschow, Y.I., Lochert, C., Scheuermann, B., Mauve, M.: CLL: a cryptographic link layer for local area networks. In: Ostrovsky, R., De Prisco, R., Visconti, I. (eds.) SCN 2008. LNCS, vol. 5229, pp. 21\u201338. Springer, Heidelberg (2008)"},{"key":"24_CR26","unstructured":"Kalige, E., Burkey, D.: Eurograbber: how 36 million euros was stolen via malware. \n                      http:\/\/www.cs.stevens.edu\/spock\/Eurograbber_White_Paper.pdf"},{"key":"24_CR27","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"56","DOI":"10.1007\/978-3-540-89862-7_4","volume-title":"Information Systems Security","author":"D King","year":"2008","unstructured":"King, D., Hicks, B., Hicks, M.W., Jaeger, T.: Implicit Flows: Can\u2019t Live with \u2018Em, Can\u2019t Live without \u2018Em. In: Sekar, R., Pujari, A.K. (eds.) ICISS 2008. LNCS, vol. 5352, pp. 56\u201370. Springer, Heidelberg (2008)"},{"key":"24_CR28","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"88","DOI":"10.1007\/978-3-540-77366-5_11","volume-title":"Financial Cryptography and Data Security","author":"MS Mannan","year":"2007","unstructured":"Mannan, M.S., van Oorschot, P.C.: Using a personal device to strengthen password authentication from an untrusted computer. In: Dietrich, S., Dhamija, R. (eds.) FC 2007 and USEC 2007. LNCS, vol. 4886, pp. 88\u2013103. Springer, Heidelberg (2007)"},{"key":"24_CR29","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"150","DOI":"10.1007\/978-3-642-39235-1_9","volume-title":"Detection of Intrusions and Malware, and Vulnerability Assessment","author":"C Mulliner","year":"2013","unstructured":"Mulliner, C., Borgaonkar, R., Stewin, P., Seifert, J.-P.: SMS-based one-time passwords: attacks and defense. In: Rieck, K., Stewin, P., Seifert, J.-P. (eds.) DIMVA 2013. LNCS, vol. 7967, pp. 150\u2013159. Springer, Heidelberg (2013)"},{"key":"24_CR30","unstructured":"Falliere, N.: Exploring Stuxnet\u2019s PLC infection process (2010). \n                      http:\/\/www.symantec.com\/connect\/blogs\/exploring-stuxnet-s-plc-infection-process"},{"key":"24_CR31","unstructured":"V. News. Teamwork: how the ZitMo Trojan bypasses online banking security (2011). \n                      http:\/\/www.kaspersky.com\/about\/news\/virus\/2011\/Teamwork_How_the_ZitMo_Trojan_Bypasses_Online_Banking_Security"},{"key":"24_CR32","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/11889663_1","volume-title":"Financial Cryptography and Data Security","author":"B Parno","year":"2006","unstructured":"Parno, B., Kuo, C., Perrig, A.: Phoolproof phishing prevention. In: Di Crescenzo, G., Rubin, A. (eds.) FC 2006. LNCS, vol. 4107, pp. 1\u201319. Springer, Heidelberg (2006)"},{"key":"24_CR33","unstructured":"Peikari, C.: Analyzing the crossover virus: the first PC to Windows handheld cross-infector (2006). \n                      http:\/\/www.informit.com\/articles\/article.aspx?p=458169"},{"key":"24_CR34","unstructured":"Schartner, P., B\u00fcrger, S.: Attacking mTAN-applications like e-banking and mobile signatures. Technical report, University of Klagenfurt (2011)"},{"key":"24_CR35","unstructured":"Sparkasse: Online banking mit chipTAN. \n                      https:\/\/www.sparkasse-pm.de\/privatkunden\/banking\/chiptan\/vorteile\/index.php?n=\/privatkunden\/banking\/chiptan\/vorteile\/"},{"key":"24_CR36","doi-asserted-by":"crossref","unstructured":"Starnberger, G., Froihofer, L., Goeschka, K.: QR-TAN: secure mobile transaction authentication. In: ARES. IEEE (2009)","DOI":"10.1109\/ARES.2009.96"},{"key":"24_CR37","volume-title":"Modern Operating Systems","author":"AS Tanenbaum","year":"2001","unstructured":"Tanenbaum, A.S.: Modern Operating Systems. Prentice Hall Press, Upper Saddle River (2001)"},{"key":"24_CR38","unstructured":"TrendLabs: 3Q 2012 security roundup. Android under siege: popularity comes at a price (2012). \n                      http:\/\/www.trendmicro.com\/cloud-content\/us\/pdfs\/security-intelligence\/reports\/rpt-3q-2012-security-roundup-android-under-siege-popularity-comes-at-a- price.pdf"},{"key":"24_CR39","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"86","DOI":"10.1007\/978-3-642-33338-5_5","volume-title":"Research in Attacks, Intrusions, and Defenses","author":"V Veen van der","year":"2012","unstructured":"van der Veen, V., dutt-Sharma, N., Cavallaro, L., Bos, H.: Memory errors: the past, the present, and the future. In: Balzarotti, D., Stolfo, S.J., Cova, M. (eds.) RAID 2012. LNCS, vol. 7462, pp. 86\u2013106. Springer, Heidelberg (2012)"},{"key":"24_CR40","doi-asserted-by":"crossref","unstructured":"Wang, Z., Stavrou, A.: Exploiting smart-phone USB connectivity for fun and profit. In: 26th Annual Computer Security Applications Conference. ACM (2010)","DOI":"10.1145\/1920261.1920314"},{"key":"24_CR41","doi-asserted-by":"crossref","unstructured":"Zhou, Y., Jiang, X.: Dissecting Android malware: characterization and evolution. In: IEEE Symposium on Security and Privacy (2012)","DOI":"10.1109\/SP.2012.16"},{"key":"24_CR42","unstructured":"Zhou, Y., Wang, Z., Zhou, W., Jiang, X.: Hey, you, get off of my market: detecting malicious apps in official and alternative Android markets. In: NDSS (2012)"}],"container-title":["Lecture Notes in Computer Science","Financial Cryptography and Data Security"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-662-45472-5_24","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,5,28]],"date-time":"2019-05-28T12:33:54Z","timestamp":1559046834000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-662-45472-5_24"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2014]]},"ISBN":["9783662454718","9783662454725"],"references-count":42,"URL":"https:\/\/doi.org\/10.1007\/978-3-662-45472-5_24","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2014]]}}}