Terminal-Assisted Web Authentication for Shared Devices with BLE-Based Confirmation Gating
In shared-device scenarios, terminal-assisted Web authentication reduces credential exposure by keeping authentication credentials on a user-carried mobile terminal. However, existing methods struggle to minimize mobile interaction while protecting against account misuse by other users of the shared device. This study proposes a session-bound, terminal-assisted Web authentication method that uses Bluetooth Low Energy (BLE) proximity evidence to adaptively tune user interaction. The method decouples identity verification from proximity-based interaction tuning: identity is verified via the mobile credential and digital signature, while proximity evidence based on the received signal strength indicator (RSSI) is used solely to determine whether explicit user confirmation on the mobile terminal can be omitted. It binds the credential, Web origin, session, proximity evidence, and selected action into a single signed transcript, restricting each response to its intended login. To handle sensing noise, an uncertainty-aware fallback policy allows the confirmation-free path only when proximity evidence is sufficient and the service policy permits it; weak or insufficient evidence requires explicit confirmation. We implemented an Android–browser–server prototype on commodity mobile terminals and shared devices without dedicated ranging hardware. In the evaluation, 93% and 82% of RSSI windows at 15 cm and 50 cm, respectively, were classified by the proximity gate as eligible for the confirmation-free path, whereas all windows at 100 cm or farther and in through-wall conditions required explicit confirmation. The measured prototype processing time averaged 1391 ms across 20 trials, excluding browser discovery, device selection, and user interaction. These results demonstrate prototype feasibility under the evaluated conditions.
Authors
- Wentao Ma (ORCID: https://orcid.org/0000-0003-3059-6629)
- Qizhen Xu (ORCID: https://orcid.org/0000-0001-9048-8887)
- Lingguang Lei (ORCID: https://orcid.org/0000-0002-1936-0562)
- Zhijie Zhang (ORCID: https://orcid.org/0000-0001-9751-8268)
- Guisen Li (ORCID: https://orcid.org/0000-0002-5189-3967)
Institutions
- Chinese Academy of Sciences (CN)
- Institute of Information Engineering (CN)
- Xiamen University of Technology (CN)
Publication Details
- Journal
- Electronics
- Published
- 2026-09-25
- DOI
- https://doi.org/10.3390/electronics15194415
- Primary Topic
- User Authentication and Security Systems
- Type
- article
- Field-Weighted Citation Impact
- 0.00