【24h】

Privacy Preserving Biometric-Based User Authentication Protocol Using Smart Cards

机译:使用智能卡的隐私保护基于生物统计的用户身份验证协议

获取原文
获取原文并翻译 | 示例

摘要

How to provide both security and privacy in communication networks has been an important issue for ubiquitous computing. Especially, user authentication in the current IT services has become one of important security issues. However, the security weaknesses in the user authentication have been exposed seriously due to the careless secret related information management and the sophisticated attack techniques. Recently, an enhanced biometric-based user authentication protocol is proposed by An, which uses three factors, password, smart card and biometrics. However, this paper shows that An's protocol has weaknesses in the password guessing attack and the lack of privacy support if an attacker could get user's smart card, could read on it and could intercept session messages between user and server. Furthermore, this paper proposes a privacy preserving biometric-based user authentication protocol using smart card, which could solve the overall problems in An's protocol and even put privacy considerations on it. The overall security analyses show that the proposed protocol achieves the desired security goals.
机译:如何在通信网络中同时提供安全性和保密性已成为普遍计算的重要问题。特别地,当前IT服务中的用户认证已经成为重要的安全问题之一。然而,由于与信息有关的粗心信息管理和复杂的攻击技术,用户身份验证中的安全漏洞已被严重暴露。最近,An提出了一种增强的基于生物特征的用户身份验证协议,该协议使用密码,智能卡和生物特征这三个因素。但是,本文表明,如果攻击者可以获取用户的智能卡,可以读取它并可以拦截用户与服务器之间的会话消息,则An的协议在密码猜测攻击方面存在缺陷,并且缺乏隐私支持。此外,本文提出了一种使用智能卡的基于隐私保护的基于生物特征的用户身份验证协议,该协议可以解决An协议中的所有问题,甚至可以考虑隐私问题。总体安全性分析表明,所提出的协议可以实现所需的安全性目标。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号