Attacks targeting several millions of non-internet based application users are on the rise. These applications such as SMS and USSD typically do not benefit from existing multi-factor authentication methods due to the nature of their interaction interfaces and mode of operations. To address this problem, we propose an approach that augments blockchain with multi-factor authentication based on evidence from blockchain transactions combined with risk analysis. A profile of how a user performs transactions is built overtime and is used to analyse the risk level of each new transaction. If a transaction is flagged as high risk, we generate n-factor layers of authentication using past endorsed blockchain transactions. A demonstration of how we used the proposed approach to authenticate critical financial transactions in a blockchain-based asset financing platform is also discussed.
翻译:针对数百万非互联网应用程序用户的袭击正在上升,例如短信管理系统和USSD等应用程序由于互动界面和运行模式的性质,一般不受益于现有的多要素认证方法。为解决这一问题,我们提议了一种办法,即根据块链交易的证据和风险分析,以多要素认证方式增加块链。关于用户如何进行交易的概况是加班建造的,用来分析每笔新交易的风险水平。如果交易被标为高风险,我们则利用过去核准的块链交易生成n要素层认证。我们还讨论了如何利用拟议的方法在块链资产融资平台上验证关键金融交易的示范。