@inproceedings{911c152c2d1b4228875abc515eefb11a,
title = "Secure display for FIDO transaction confirmation",
abstract = "FIDO protocols enable online services to leverage native authenticators of end-user computing devices including fingerprint readers for authentication to replace or complement passwords. FIDO protocols also offer support for prompting a user to confirm a specific transaction. However, due to the lack of a trusted display module in most Authenticators, operating systems of user devices display transaction contents directly on the main screen. In the paper, we demonstrate an attack on FIDO transaction confirmation in which malicious applications leverage the disparity between the displayed and actual transaction contents to trick users into confirming falsified transactions. In addition, we propose a lightweight secure display mechanism for FIDO transaction confirmations on mobile devices by leveraging the ARM TrustZone technology.",
keywords = "FIDO, Secure Display, Transaction Confirmation",
author = "Yongxian Zhang and Xinluo Wang and Ziming Zhao and Hui Li",
note = "Publisher Copyright: {\textcopyright} 2018 Copyright held by the owner/author(s).; 8th ACM Conference on Data and Application Security and Privacy, CODASPY 2018 ; Conference date: 19-03-2018 Through 21-03-2018",
year = "2018",
month = mar,
day = "13",
doi = "10.1145/3176258.3176946",
language = "English",
series = "CODASPY 2018 - Proceedings of the 8th ACM Conference on Data and Application Security and Privacy",
publisher = "Association for Computing Machinery ",
pages = "155--157",
booktitle = "CODASPY 2018 - Proceedings of the 8th ACM Conference on Data and Application Security and Privacy",
address = "United States",
}