{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T04:14:12Z","timestamp":1750220052141,"version":"3.41.0"},"publisher-location":"New York, NY, USA","reference-count":42,"publisher":"ACM","license":[{"start":{"date-parts":[[2023,7,10]],"date-time":"2023-07-10T00:00:00Z","timestamp":1688947200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2023,7,10]]},"DOI":"10.1145\/3579856.3595800","type":"proceedings-article","created":{"date-parts":[[2023,7,5]],"date-time":"2023-07-05T14:52:13Z","timestamp":1688568733000},"page":"884-898","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["Formalising Application-Driven Authentication &amp; Access-Control based on Users\u2019 Companion Devices"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-9543-1342","authenticated-orcid":false,"given":"Chris","family":"Culnane","sequence":"first","affiliation":[{"name":"Castellate Consulting Ltd, United Kingdom"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5864-777X","authenticated-orcid":false,"given":"Ioana","family":"Boureanu","sequence":"additional","affiliation":[{"name":"Surrey Centre for Cyber Security, University of Surrey, United Kingdom"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4662-7760","authenticated-orcid":false,"given":"Jean","family":"Snyman","sequence":"additional","affiliation":[{"name":"Surrey Centre for Cyber Security, University of Surrey, United Kingdom"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7167-0146","authenticated-orcid":false,"given":"Stephan","family":"Wesemeyer","sequence":"additional","affiliation":[{"name":"Surrey Centre for Cyber Security, University of Surrey, United Kingdom"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1835-4803","authenticated-orcid":false,"given":"Helen","family":"Treharne","sequence":"additional","affiliation":[{"name":"Surrey Centre for Cyber Security, University of Surrey, United Kingdom"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2023,7,10]]},"reference":[{"key":"e_1_3_2_1_2_1","unstructured":"FIDO Alliance. 2023. User Authentication Specifications Overview. https:\/\/fidoalliance.org\/specifications\/.  FIDO Alliance. 2023. User Authentication Specifications Overview. https:\/\/fidoalliance.org\/specifications\/."},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"crossref","unstructured":"A. Armando D. Basin Y. Boichut and etal2005. The AVISPA Tool for the Automated Validation of Internet Security Protocols and Applications. In CAV.  A. Armando D. Basin Y. Boichut and et al.2005. The AVISPA Tool for the Automated Validation of Internet Security Protocols and Applications. In CAV.","DOI":"10.1007\/11513988_27"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"crossref","unstructured":"David Basin Jannik Dreier Lucca Hirschi Sa\u0161a Radomirovic Ralf Sasse and Vincent Stettler. 2018. A Formal Analysis of 5G Authentication. In CCS. 1383\u20131396.  David Basin Jannik Dreier Lucca Hirschi Sa\u0161a Radomirovic Ralf Sasse and Vincent Stettler. 2018. A Formal Analysis of 5G Authentication. In CCS. 1383\u20131396.","DOI":"10.1145\/3243734.3243846"},{"key":"e_1_3_2_1_5_1","volume-title":"Fix, Verify. In Security and Privacy (SP)","author":"Basin A.","year":"2021","unstructured":"David\u00a0 A. Basin , Ralf Sasse , and Jorge Toro-Pozo . 2021. The EMV Standard: Break , Fix, Verify. In Security and Privacy (SP) 2021 . David\u00a0A. Basin, Ralf Sasse, and Jorge Toro-Pozo. 2021. The EMV Standard: Break, Fix, Verify. In Security and Privacy (SP) 2021."},{"volume-title":"An Efficient Cryptographic Protocol Verifier Based on Prolog Rules","author":"Blanchet B.","key":"e_1_3_2_1_6_1","unstructured":"B. Blanchet . 2001. An Efficient Cryptographic Protocol Verifier Based on Prolog Rules . In IEEE CSFW. B. Blanchet. 2001. An Efficient Cryptographic Protocol Verifier Based on Prolog Rules. In IEEE CSFW."},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"crossref","unstructured":"Bruno Blanchet. 2012. Security Protocol Verification: Symbolic and Computational Models. In PST. 3\u201329.  Bruno Blanchet. 2012. Security Protocol Verification: Symbolic and Computational Models. In PST. 3\u201329.","DOI":"10.1007\/978-3-642-28641-4_2"},{"key":"e_1_3_2_1_8_1","unstructured":"Christiaan Brand and et\u00a0al. Alexei\u00a0Czeskis. 2019. Client to Authenticator Protocol (CTAP). Prop. FIDO Alliance. https:\/\/fidoalliance.org\/specs\/fido-v2.0-ps-20190130\/fido-client-to-authenticator-protocol-v2.0-ps-20190130.html.  Christiaan Brand and et\u00a0al. Alexei\u00a0Czeskis. 2019. Client to Authenticator Protocol (CTAP). Prop. FIDO Alliance. https:\/\/fidoalliance.org\/specs\/fido-v2.0-ps-20190130\/fido-client-to-authenticator-protocol-v2.0-ps-20190130.html."},{"key":"e_1_3_2_1_9_1","article-title":"A BRIEF REVIEW ABOUT BIOMETRICS SYSTEMS IN MODERN CONTEXT","volume":"13","author":"Caballero-Hern\u00e1ndez H\u00e9ctor","year":"2022","unstructured":"H\u00e9ctor Caballero-Hern\u00e1ndez , Leopoldo Gil-Antonio , Erika Lopez-Gonzalez , and Juan\u00a0Alberto Antonio-Velazquez . 2022 . A BRIEF REVIEW ABOUT BIOMETRICS SYSTEMS IN MODERN CONTEXT . Int. J. of Advanced Research in Computer Science 13 , 3 (2022). H\u00e9ctor Caballero-Hern\u00e1ndez, Leopoldo Gil-Antonio, Erika Lopez-Gonzalez, and Juan\u00a0Alberto Antonio-Velazquez. 2022. A BRIEF REVIEW ABOUT BIOMETRICS SYSTEMS IN MODERN CONTEXT. Int. J. of Advanced Research in Computer Science 13, 3 (2022).","journal-title":"Int. J. of Advanced Research in Computer Science"},{"key":"e_1_3_2_1_10_1","volume-title":"A Unified Framework for Analyzing Security of Protocols. ECCC 8, 16","author":"Canetti R.","year":"2001","unstructured":"R. Canetti . 2001. A Unified Framework for Analyzing Security of Protocols. ECCC 8, 16 ( 2001 ). R. Canetti. 2001. A Unified Framework for Analyzing Security of Protocols. ECCC 8, 16 (2001)."},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"crossref","unstructured":"Dhiman Chakraborty and Sven Bugiel. 2019. simFIDO: FIDO2 User Authentication with simTPM. In CCS. 2569\u20132571.  Dhiman Chakraborty and Sven Bugiel. 2019. simFIDO: FIDO2 User Authentication with simTPM. In CCS. 2569\u20132571.","DOI":"10.1145\/3319535.3363258"},{"key":"e_1_3_2_1_12_1","volume-title":"van\u00a0der Merwe","author":"Cremers C.","year":"2016","unstructured":"C. Cremers , M. Horvat , S. Scott , and T. van\u00a0der Merwe . 2016 . Automated analysis and verification of TLS 1.3: 0-RTT, resumption and delayed authentication. In SP. C. Cremers, M. Horvat, S. Scott, and T. van\u00a0der Merwe. 2016. Automated analysis and verification of TLS 1.3: 0-RTT, resumption and delayed authentication. In SP."},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"crossref","unstructured":"C.J.F. Cremers and S. Mauw. 2004. Operational semantics of security protocols. Technische Universiteit Eindhoven.  C.J.F. Cremers and S. Mauw. 2004. Operational semantics of security protocols. Technische Universiteit Eindhoven.","DOI":"10.1007\/11495628_4"},{"key":"e_1_3_2_1_14_1","unstructured":"Chris Culnane Ioana Boureanu Helen Treharne Jean Snyman and Steve Wesemeyer. 2023. Our Code Proof and Tamarin Files. https:\/\/github.com\/UoS-SCCS\/CompendiumDevice-Project. Online: 2022-12-15.  Chris Culnane Ioana Boureanu Helen Treharne Jean Snyman and Steve Wesemeyer. 2023. Our Code Proof and Tamarin Files. https:\/\/github.com\/UoS-SCCS\/CompendiumDevice-Project. Online: 2022-12-15."},{"key":"e_1_3_2_1_15_1","unstructured":"Garrett Davidson. 2021. Move beyond Passwords - WWDC21 - Videos. https:\/\/developer.apple.com\/videos\/play\/wwdc2021\/10106\/.  Garrett Davidson. 2021. Move beyond Passwords - WWDC21 - Videos. https:\/\/developer.apple.com\/videos\/play\/wwdc2021\/10106\/."},{"key":"e_1_3_2_1_16_1","volume-title":"Meet Passkeys. https:\/\/developer.apple.com\/videos\/play\/wwdc2022\/10092\/.","author":"Davidson Garrett","year":"2022","unstructured":"Garrett Davidson . 2022 . Meet Passkeys. https:\/\/developer.apple.com\/videos\/play\/wwdc2022\/10092\/. Garrett Davidson. 2022. Meet Passkeys. https:\/\/developer.apple.com\/videos\/play\/wwdc2022\/10092\/."},{"key":"e_1_3_2_1_17_1","unstructured":"Dell. 2023. Precision 3660 Tower. https:\/\/www.dell.com\/en-uk\/shop\/workstations\/precision-3660-tower-workstation\/spd\/precision-3660-workstation\/.  Dell. 2023. Precision 3660 Tower. https:\/\/www.dell.com\/en-uk\/shop\/workstations\/precision-3660-tower-workstation\/spd\/precision-3660-workstation\/."},{"key":"e_1_3_2_1_18_1","volume-title":"Authentication and authenticated key exchanges. Designs, Codes and cryptography 2, 2","author":"Diffie Whitfield","year":"1992","unstructured":"Whitfield Diffie , Paul\u00a0 C Van\u00a0Oorschot , and Michael\u00a0 J Wiener . 1992. Authentication and authenticated key exchanges. Designs, Codes and cryptography 2, 2 ( 1992 ), 107\u2013125. Whitfield Diffie, Paul\u00a0C Van\u00a0Oorschot, and Michael\u00a0J Wiener. 1992. Authentication and authenticated key exchanges. Designs, Codes and cryptography 2, 2 (1992), 107\u2013125."},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"crossref","unstructured":"D. Dolev and A. Yao. 1983. On the Security of Public-Key Protocols. IEEE Transactionson Information Theory 29 29 2 (1983).  D. Dolev and A. Yao. 1983. On the Security of Public-Key Protocols. IEEE Transactionson Information Theory 29 29 2 (1983).","DOI":"10.1109\/TIT.1983.1056650"},{"key":"e_1_3_2_1_20_1","unstructured":"Aymeric\u00a0Augustin et. al.2023. Python websockets library. https:\/\/websockets.readthedocs.io\/en\/stable\/.  Aymeric\u00a0Augustin et. al.2023. Python websockets library. https:\/\/websockets.readthedocs.io\/en\/stable\/."},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"crossref","unstructured":"Ihor Filimonov Ross Horne Sjouke Mauw and Zach Smith. 2019. Breaking Unlinkability of the ICAO 9303 Standard for e-Passports Using Bisimilarity. In ESORICS Kazue Sako Steve Schneider and Peter Y.\u00a0A. Ryan (Eds.). 577\u2013594.  Ihor Filimonov Ross Horne Sjouke Mauw and Zach Smith. 2019. Breaking Unlinkability of the ICAO 9303 Standard for e-Passports Using Bisimilarity. In ESORICS Kazue Sako Steve Schneider and Peter Y.\u00a0A. Ryan (Eds.). 577\u2013594.","DOI":"10.1007\/978-3-030-29959-0_28"},{"volume-title":"Foundations of Cryptography","author":"Goldreich O.","key":"e_1_3_2_1_22_1","unstructured":"O. Goldreich . 2006. Foundations of Cryptography : Volume 1 . Cambridge University Press , New York, NY, USA . O. Goldreich. 2006. Foundations of Cryptography: Volume 1. Cambridge University Press, New York, NY, USA."},{"key":"e_1_3_2_1_23_1","unstructured":"Google. 2023. Get Verification Codes with Google Authenticator. https:\/\/support.google.com\/accounts\/answer\/1066447.  Google. 2023. Get Verification Codes with Google Authenticator. https:\/\/support.google.com\/accounts\/answer\/1066447."},{"key":"e_1_3_2_1_24_1","unstructured":"Shawn Hickey. 2021. Windows Unlock with Windows Hello Companion (IoT) Devices. docs.microsoft.com\/en-us\/windows\/uwp\/security\/companion-device-unlock.  Shawn Hickey. 2021. Windows Unlock with Windows Hello Companion (IoT) Devices. docs.microsoft.com\/en-us\/windows\/uwp\/security\/companion-device-unlock."},{"key":"e_1_3_2_1_25_1","unstructured":"Eiji Kitamura. 2022. A Path to a World without Passwords. https:\/\/io.google\/.  Eiji Kitamura. 2022. A Path to a World without Passwords. https:\/\/io.google\/."},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"crossref","unstructured":"Eric Klieme Jonathan Wilke Niklas van Dornick and Christoph Meinel. 2020. FIDOnuous: A FIDO2\/WebAuthn Extension to Support Continuous Web Authentication. In TrustCom. 1857\u20131867.  Eric Klieme Jonathan Wilke Niklas van Dornick and Christoph Meinel. 2020. FIDOnuous: A FIDO2\/WebAuthn Extension to Support Continuous Web Authentication. In TrustCom. 1857\u20131867.","DOI":"10.1109\/TrustCom50675.2020.00254"},{"key":"e_1_3_2_1_27_1","unstructured":"Kim Komando. 2023. Bluetooth security risks to know (and how to avoid them). https:\/\/eu.usatoday.com\/story\/tech\/columnist\/komando\/2023\/02\/26\/leaving-your-phones-bluetooth-24-7-can-major-security-risk\/11308150002\/.  Kim Komando. 2023. Bluetooth security risks to know (and how to avoid them). https:\/\/eu.usatoday.com\/story\/tech\/columnist\/komando\/2023\/02\/26\/leaving-your-phones-bluetooth-24-7-can-major-security-risk\/11308150002\/."},{"key":"e_1_3_2_1_28_1","first-page":"e3","article-title":"BluePass: A Mobile Device Assisted Password Manager","volume":"5","author":"Li Yue","year":"2018","unstructured":"Yue Li , Haining Wang , and Kun Sun . 2018 . BluePass: A Mobile Device Assisted Password Manager . EAI ETSS 5 , 17 (2018), e3 . Yue Li, Haining Wang, and Kun Sun. 2018. BluePass: A Mobile Device Assisted Password Manager. EAI ETSS 5, 17 (2018), e3.","journal-title":"EAI ETSS"},{"volume-title":"A hierarchy of authentication specifications","author":"Lowe Gavin","key":"e_1_3_2_1_29_1","unstructured":"Gavin Lowe . 1997. A hierarchy of authentication specifications . In CSFW. IEEE , 31\u201343. Gavin Lowe. 1997. A hierarchy of authentication specifications. In CSFW. IEEE, 31\u201343."},{"key":"e_1_3_2_1_30_1","volume-title":"Web Authentication: An API for Accessing Public Key Credentials - Level 2. Recommendation","author":"Lundberg Emil","year":"2021","unstructured":"Emil Lundberg , Michael Jones , J.\u00a0 C. Jones , Akshay Kumar , and Jeff Hodges . 2021 . Web Authentication: An API for Accessing Public Key Credentials - Level 2. Recommendation . World Wide Web Consortium (W 3C). https:\/\/www.w3.org\/TR\/webauthn-2\/. Emil Lundberg, Michael Jones, J.\u00a0C. Jones, Akshay Kumar, and Jeff Hodges. 2021. Web Authentication: An API for Accessing Public Key Credentials - Level 2. Recommendation. World Wide Web Consortium (W3C). https:\/\/www.w3.org\/TR\/webauthn-2\/."},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/2420950.2420964"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"crossref","unstructured":"S. Meier B. Schmidt C. Cremers and D. Basin. 2013. The TAMARIN Prover for the Symbolic Analysis of Security Protocols. In CAV (Saint Petersburg Russia). 696\u2013701.  S. Meier B. Schmidt C. Cremers and D. Basin. 2013. The TAMARIN Prover for the Symbolic Analysis of Security Protocols. In CAV (Saint Petersburg Russia). 696\u2013701.","DOI":"10.1007\/978-3-642-39799-8_48"},{"key":"e_1_3_2_1_33_1","unstructured":"Ioan Moldovan. 2021. FiSSH: SSH Authentication via Fingerprint Scanning over Network (TLS Sockets). https:\/\/f-droid.org\/.  Ioan Moldovan. 2021. FiSSH: SSH Authentication via Fingerprint Scanning over Network (TLS Sockets). https:\/\/f-droid.org\/."},{"key":"e_1_3_2_1_34_1","unstructured":"Stephen Perkins. 2019. How to Use Your Phone\u2019s Fingerprint Scanner to Unlock Your Windows PC. https:\/\/android.gadgethacks.com\/how-to\/use-your-phones-fingerprint-scanner-unlock-your-windows-pc-0192636\/.  Stephen Perkins. 2019. How to Use Your Phone\u2019s Fingerprint Scanner to Unlock Your Windows PC. https:\/\/android.gadgethacks.com\/how-to\/use-your-phones-fingerprint-scanner-unlock-your-windows-pc-0192636\/."},{"key":"e_1_3_2_1_35_1","unstructured":"Matthew Prince Daniel Stinson-Diess and Sourov Zaman. 2022. The Mechanics of a Sophisticated Phishing Scam and How We Stopped It. http:\/\/blog.cloudflare.com\/2022-07-sms-phishing-attacks\/.  Matthew Prince Daniel Stinson-Diess and Sourov Zaman. 2022. The Mechanics of a Sophisticated Phishing Scam and How We Stopped It. http:\/\/blog.cloudflare.com\/2022-07-sms-phishing-attacks\/."},{"key":"e_1_3_2_1_36_1","unstructured":"Dominik Reichl. 2023. KeePass Password Safe. https:\/\/keepass.info\/.  Dominik Reichl. 2023. KeePass Password Safe. https:\/\/keepass.info\/."},{"key":"e_1_3_2_1_37_1","unstructured":"V. Shoup. [n. d.]. Sequences of games: a tool for taming complexity in security proofs. ePrint 2004 ([n. d.]).  V. Shoup. [n. d.]. Sequences of games: a tool for taming complexity in security proofs. ePrint 2004 ([n. d.])."},{"key":"e_1_3_2_1_38_1","unstructured":"Clare Stouffer. 2022. Bluetooth security risks to know (and how to avoid them). https:\/\/us.norton.com\/blog\/mobile\/bluetooth-security.  Clare Stouffer. 2022. Bluetooth security risks to know (and how to avoid them). https:\/\/us.norton.com\/blog\/mobile\/bluetooth-security."},{"volume-title":"Trusted Platform Module 2.0 Library Specification. Rev 1.59","author":"TCG.","key":"e_1_3_2_1_39_1","unstructured":"TCG. 2019. Trusted Platform Module 2.0 Library Specification. Rev 1.59 . Trusted Computing Group . https:\/\/trustedcomputinggroup.org\/resource\/tpm-library-specification\/ TCG. 2019. Trusted Platform Module 2.0 Library Specification. Rev 1.59. Trusted Computing Group. https:\/\/trustedcomputinggroup.org\/resource\/tpm-library-specification\/"},{"key":"e_1_3_2_1_40_1","unstructured":"Twilio Inc.2023. Two-Factor Authentication (2FA) App. https:\/\/authy.com\/.  Twilio Inc.2023. Two-Factor Authentication (2FA) App. https:\/\/authy.com\/."},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"crossref","unstructured":"Paul Wagner Kris Heid and Jens Heider. 2021. Remote WebAuthn: FIDO2 Authentication for Less Accessible Devices:. In ISSP. 368\u2013375.  Paul Wagner Kris Heid and Jens Heider. 2021. Remote WebAuthn: FIDO2 Authentication for Less Accessible Devices:. In ISSP. 368\u2013375.","DOI":"10.5220\/0010192703680375"},{"key":"e_1_3_2_1_42_1","unstructured":"Yubico. 2023. Yubico Home. https:\/\/www.yubico.com\/.  Yubico. 2023. Yubico Home. https:\/\/www.yubico.com\/."},{"key":"e_1_3_2_1_43_1","volume-title":"NoKey - A Distributed Password Manager. Master\u2019s thesis","author":"Zinggeler Florian","year":"2017","unstructured":"Florian Zinggeler . 2018. NoKey - A Distributed Password Manager. Master\u2019s thesis . Swiss Federal Institute of Technology Zurich . https:\/\/pub.tik.ee.ethz.ch\/students\/ 2017 -HS\/MA-2017-24.pdf. Florian Zinggeler. 2018. NoKey - A Distributed Password Manager. Master\u2019s thesis. Swiss Federal Institute of Technology Zurich. https:\/\/pub.tik.ee.ethz.ch\/students\/2017-HS\/MA-2017-24.pdf."}],"event":{"name":"ASIA CCS '23: ACM ASIA Conference on Computer and Communications Security","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"],"location":"Melbourne VIC Australia","acronym":"ASIA CCS '23"},"container-title":["Proceedings of the ACM Asia Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3579856.3595800","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T18:08:17Z","timestamp":1750183697000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3579856.3595800"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,7,10]]},"references-count":42,"alternative-id":["10.1145\/3579856.3595800","10.1145\/3579856"],"URL":"https:\/\/doi.org\/10.1145\/3579856.3595800","relation":{},"subject":[],"published":{"date-parts":[[2023,7,10]]},"assertion":[{"value":"2023-07-10","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}