{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,19]],"date-time":"2026-06-19T02:17:55Z","timestamp":1781835475289,"version":"3.54.5"},"publisher-location":"New York, NY, USA","reference-count":41,"publisher":"ACM","license":[{"start":{"date-parts":[[2023,8,29]],"date-time":"2023-08-29T00:00:00Z","timestamp":1693267200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2023,8,29]]},"DOI":"10.1145\/3600160.3600165","type":"proceedings-article","created":{"date-parts":[[2023,8,9]],"date-time":"2023-08-09T22:54:41Z","timestamp":1691621681000},"page":"1-11","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":4,"title":["Actions Speak Louder Than Passwords: Dynamic Identity for Machine-to-Machine Communication"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0008-0620-1379","authenticated-orcid":false,"given":"Wil Liam","family":"Teng","sequence":"first","affiliation":[{"name":"University of Oxford, United Kingdom"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9471-9985","authenticated-orcid":false,"given":"Kasper","family":"Rasmussen","sequence":"additional","affiliation":[{"name":"University of Oxford, United Kingdom"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2023,8,29]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243839"},{"key":"e_1_3_2_1_2_1","unstructured":"aws. 2022. Creating and using usage plans with API keys. Available: https:\/\/docs.aws.amazon.com\/apigateway\/latest\/developerguide\/api-gateway-api-usage-plans.html."},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP48549.2020.00044"},{"key":"e_1_3_2_1_4_1","unstructured":"Matt Binder. 2022. A teen hacked Uber and announced it in the company Slack. Employees thought it was a joke.Available: https:\/\/mashable.com\/article\/uber-teen-hacker-slack-joke."},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.3390\/sym10080352"},{"key":"e_1_3_2_1_6_1","volume-title":"Workshop on the Theory and Application of Cryptographic Techniques Lofthus, Norway, May 23\u201327, 1993 Proceedings 12","author":"Brands Stefan","year":"1994","unstructured":"Stefan Brands and David Chaum. 1994. Distance-bounding protocols. In Advances in Cryptology\u2014EUROCRYPT\u201993: Workshop on the Theory and Application of Cryptographic Techniques Lofthus, Norway, May 23\u201327, 1993 Proceedings 12. Springer, 344\u2013359."},{"key":"e_1_3_2_1_7_1","volume-title":"Version 1","author":"Campagna Matthew","year":"2013","unstructured":"Matthew Campagna. 2013. SEC 4: Elliptic curve Qu-Vanstone implicit certificate scheme (ECQV). Standards for Efficient Cryptography, Version 1 (2013)."},{"key":"e_1_3_2_1_8_1","volume-title":"Building PUF based authentication and key exchange protocol for IoT without explicit CRPs in verifier database","author":"Chatterjee Urbi","year":"2018","unstructured":"Urbi Chatterjee, Vidya Govindan, Rajat Sadhukhan, Debdeep Mukhopadhyay, Rajat\u00a0Subhra Chakraborty, Debashis Mahata, and Mukesh\u00a0M Prabhu. 2018. Building PUF based authentication and key exchange protocol for IoT without explicit CRPs in verifier database. IEEE transactions on dependable and secure computing 16, 3 (2018), 424\u2013437."},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1016\/S1361-3723(97)82613-9"},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIT.1983.1056650"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2017.2737630"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813726"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1007\/s11277-020-07645-z"},{"key":"e_1_3_2_1_16_1","unstructured":"GitHub Docs. [n.d.]. Creating a personal access token. Available: https:\/\/docs.github.com\/en\/authentication\/keeping-your-account-and-data-secure\/creating-a-personal-access-token."},{"key":"e_1_3_2_1_17_1","unstructured":"Google Cloud. 2022. Authenticate using API keys. Available: https:\/\/cloud.google.com\/docs\/authentication\/api-keys."},{"key":"e_1_3_2_1_18_1","volume-title":"UPPRESSO: Untraceable and Unlinkable Privacy-PREserving Single Sign-On Services. arXiv preprint arXiv:2110.10396","author":"Guo Chengqian","year":"2021","unstructured":"Chengqian Guo, Jingqiang Lin, Quanwei Cai, Fengjun Li, Qiongxiao Wang, Jiwu Jing, Bin Zhao, and Wei Wang. 2021. UPPRESSO: Untraceable and Unlinkable Privacy-PREserving Single Sign-On Services. arXiv preprint arXiv:2110.10396 (2021)."},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-99073-6_23"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2019.2919926"},{"key":"e_1_3_2_1_21_1","unstructured":"Mike Hanley. 2022. Security alert: Attack campaign involving stolen OAuth user tokens issued to two third-party integrators. Available: https:\/\/github.blog\/2022-04-15-security-alert-stolen-oauth-user-tokens\/."},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICUFN.2013.6614820"},{"key":"e_1_3_2_1_25_1","unstructured":"IBM. 2022. Creating an IBM Cloud API key. Available: https:\/\/www.ibm.com\/docs\/en\/app-connect\/container?topic=servers-creating-cloud-api-key."},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-23829-6_8"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.3390\/s20020501"},{"key":"e_1_3_2_1_28_1","first-page":"94","article-title":"Security assertion markup language (saml) v2. 0 technical overview","volume":"2","author":"Lockhart Hal","year":"2008","unstructured":"Hal Lockhart and B Campbell. 2008. Security assertion markup language (saml) v2. 0 technical overview. OASIS Committee Draft 2 (2008), 94\u2013106.","journal-title":"OASIS Committee Draft"},{"key":"e_1_3_2_1_29_1","volume-title":"Context-aware authentication: State-of-the-art evaluation and adaption to the IIoT. In 2019 IEEE 5th World Forum on Internet of Things (WF-IoT)","author":"Loske Moritz","unstructured":"Moritz Loske, Lukas Rothe, and Dominik\u00a0G Gertler. 2019. Context-aware authentication: State-of-the-art evaluation and adaption to the IIoT. In 2019 IEEE 5th World Forum on Internet of Things (WF-IoT). IEEE, 64\u201369."},{"key":"e_1_3_2_1_30_1","unstructured":"Microsoft. 2022. Use API keys for Azure Cognitive Search authentication. Available: https:\/\/learn.microsoft.com\/en-us\/azure\/search\/search-security-api-keys#what-is-an-api-key."},{"key":"e_1_3_2_1_31_1","unstructured":"Greg Ose. 2022. npm security update: Attack campaign using stolen OAuth tokens. Available: https:\/\/github.blog\/2022-05-26-npm-security-update-oauth-tokens\/."},{"key":"e_1_3_2_1_32_1","unstructured":"Kasper\u00a0Bonne Rasmussen and Srdjan Capkun. 2010. Realization of RF Distance Bounding.. In USENIX security symposium. 389\u2013402."},{"key":"e_1_3_2_1_33_1","volume-title":"PAS-TA-U: PASsword-Based Threshold Authentication with Password Update. In International Conference on Security, Privacy, and Applied Cryptography Engineering. Springer, 25\u201345","author":"Rawat Rachit","year":"2020","unstructured":"Rachit Rawat and Mahabir\u00a0Prasad Jhanwar. 2020. PAS-TA-U: PASsword-Based Threshold Authentication with Password Update. In International Conference on Security, Privacy, and Applied Cryptography Engineering. Springer, 25\u201345."},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2908499"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1007\/s13389-021-00283-6"},{"key":"e_1_3_2_1_36_1","volume-title":"Openid connect core 1.0","author":"Sakimura Natsuhiko","year":"2014","unstructured":"Natsuhiko Sakimura, John Bradley, Mike Jones, Breno De\u00a0Medeiros, and Chuck Mortimore. 2014. Openid connect core 1.0. The OpenID Foundation (2014), S3."},{"key":"e_1_3_2_1_37_1","unstructured":"Statista Research Department. 2022. M2M (machine-to-machine) \u2013 Statistics & Facts. https:\/\/www.statista.com\/topics\/1843\/m2m-machine-to-machine\/."},{"key":"e_1_3_2_1_38_1","volume-title":"Kerberos: An Authentication Service for Open Network Systems. In IN USENIX CONFERENCE PROCEEDINGS. 191\u2013202.","author":"Steiner G.","year":"1988","unstructured":"Jennifer\u00a0G. Steiner, Clifford Neuman, and Jeffrey\u00a0I. Schiller. 1988. Kerberos: An Authentication Service for Open Network Systems. In IN USENIX CONFERENCE PROCEEDINGS. 191\u2013202."},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1109\/iEECON51072.2021.9440355"},{"key":"e_1_3_2_1_40_1","first-page":"30059","article-title":"Data Breach Investigations Report 2020","volume":"4","author":"Verizon DBIR","year":"2020","unstructured":"DBIR Verizon. 2020. Data Breach Investigations Report 2020. Computer Fraud & Security 4 (2020), 30059\u20132.","journal-title":"Computer Fraud & Security"},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1109\/TrustCom.2012.198"},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1109\/TMC.2020.2975792"},{"key":"e_1_3_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.2478\/popets-2021-0018"},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"crossref","unstructured":"Zhenfeng Zhang Yuchen Wang and Kang Yang. 2020. Strong Authentication without Temper-Resistant Hardware and Application to Federated Identities.. In NDSS.","DOI":"10.14722\/ndss.2020.24462"},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1109\/CMC.2010.232"}],"event":{"name":"ARES 2023: The 18th International Conference on Availability, Reliability and Security","location":"Benevento Italy","acronym":"ARES 2023"},"container-title":["Proceedings of the 18th International Conference on Availability, Reliability and Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3600160.3600165","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3600160.3600165","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T16:36:13Z","timestamp":1750178173000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3600160.3600165"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,8,29]]},"references-count":41,"alternative-id":["10.1145\/3600160.3600165","10.1145\/3600160"],"URL":"https:\/\/doi.org\/10.1145\/3600160.3600165","relation":{},"subject":[],"published":{"date-parts":[[2023,8,29]]},"assertion":[{"value":"2023-08-29","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}