首页> 外文会议>2015 Third International Conference on Computer, Communication, Control and Information Technology >Enhancing security of one-time password using Elliptic Curve Cryptography with biometrics for e-commerce applications
【24h】

Enhancing security of one-time password using Elliptic Curve Cryptography with biometrics for e-commerce applications

机译:使用椭圆曲线密码术和生物识别技术为电子商务应用增强一次性密码的安全性

获取原文
获取原文并翻译 | 示例

摘要

Security of one-time password (OTP) is essential because nowadays most of the e-commerce transactions are performed with the help of this mechanism. OTP is used to counter replay attack/eavesdropping. Replay attack or eavesdropping is one type of attacks on network-connected computing environment or isolated computing environment. For achieving 112 bits of security level, Rivest Shamir and Adleman (RSA) algorithm needs key size of 2048 bits, while Elliptic Curve Cryptography (ECC) needs key size of 224-255 bits. Another issue with most of the existing implementation of security models is storage of secret keys. Cryptographic keys are often kept in en-secured way that can either be guessed/social-engineered or obtained through brute force attacks. This becomes a weak link and leads integrity issues of sensitive data in a security model. To overcome the above problem, biometrics is combined with cryptography for developing strong security model. This paper suggests an enhanced security model of OTP system using ECC with palm-vein biometrie. This model also suggests better security with lesser key size than other prevalent public key crypto-model. The cryptographic keys are also not required to memorize or keep anywhere, these keys are generated as and when needed.
机译:一次性密码(OTP)的安全性至关重要,因为当今大多数电子商务交易都是借助此机制执行的。 OTP用于抵抗重播攻击/窃听。重播攻击或窃听是对网络连接的计算环境或隔离的计算环境的一种攻击。为了达到112位的安全级别,Rivest Shamir和Adleman(RSA)算法需要2048位的密钥大小,而椭圆曲线密码术(ECC)需要224-255位的密钥大小。大多数现有安全模型实现的另一个问题是密钥的存储。密码密钥通常以安全的方式保存,可以通过猜测/社交工程或通过蛮力攻击获得。这将成为一个薄弱的环节,并在安全模型中引发敏感数据的完整性问题。为了克服上述问题,将生物识别技术与密码学相结合以开发强大的安全模型。本文提出了一种使用ECC和掌静脉生物特征的OTP系统增强安全模型。该模型还提出了比其他流行的公共密钥加密模型更好的安全性,并且密钥大小更小。也不要求密码密钥存储或保存在任何地方,这些密钥在需要时生成。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号