Research Article

Authenticator Rebinding Attack of the UAF Protocol on Mobile Devices

Table 3

In-App Authenticator Mode libraries and applications.

Library package nameAttack effectivenessApplication package nameCode protection measureDownloads (million)

cn.com.union.fidoāˆšcom.jd.jrappCode obfuscation23.83
com.csii.sns.uiApp reinforcement0.80
com.cebbank.mobile.cembApp reinforcement0.36
cn.com.bhbc.mobilebank.perApp reinforcement0.30
com.chinamworld.klbApp reinforcement0.06
cn.com.gdbank.directApp reinforcement0.01
com.csii.ly.uiApp reinforcement0.01
com.csii.wjnsbankApp reinforcementLess than 0.01
com.urthinker.langfangbank.lfbankApp reinforcementLess than 0.01
com.csii.yk.uiApp reinforcementLess than 0.01
com.csii.zbdirectApp reinforcementLess than 0.01

com.daon.fido.client.sdkUnconfirmedcom.bochk.comCode obfuscation0.05

com.fido.android.frameworkUnconfirmedcom.chinatelecom.bestpayclientApp reinforcement34.45

com.iss.sdpersonalbank.fidofingerUnconfirmedcom.iss.weifangbankApp reinforcement0.17
com.iss.rizhaobankApp reinforcement0.13
com.uccb.mobileApp reinforcement0.13
com.iss.changanbankApp reinforcement0.12
com.iss.weihaibankApp reinforcement0.10
com.iss.qilubankApp reinforcement0.09
com.iss.qishangbankApp reinforcement0.09
com.iss.jiningbankApp reinforcement0.08
com.iss.taianbankApp reinforcement0.08
com.iss.dongyingbankApp reinforcement0.07
com.iss.laishangbankApp reinforcement0.07
com.iss.ysantaibankApp reinforcement0.07
com.iss.dezhoubankApp reinforcement0.06
com.iss.zaozhuangbankApp reinforcement0.02

com.lenovo.fido.frameworkUnconfirmedcom.baidu.walletApp reinforcement1.69
com.bill99.kuaiqianApp reinforcement1.58

UnknownUnconfirmedcom.icbcApp reinforcement69.67
com.chinamworld.bocmbciApp reinforcement38.06
com.icbc.imApp reinforcement22.57
com.baixin.mobilebankApp reinforcement0.52
com.icbc.collegestudentsApp reinforcement0.11