首页> 外文会议>International Conference оп Computing for Sustainable Global Development >Enhancing security of one-time password using Elliptic Curve Cryptography with finger-print biometric
【24h】

Enhancing security of one-time password using Elliptic Curve Cryptography with finger-print biometric

机译:椭圆曲线密码术和指纹生物识别技术提高一次性密码的安全性

获取原文

摘要

Security of one-time password (OTP) is essential because nowadays most of the e-commerce transactions are performed with the help of this mechanism. OTP is used to counter replay attack / eavesdropping. Replay Attack / eavesdropping is one form of attack on computing system connected to the Internet or Intranet. For achieving 112 bits of security level, RSA algorithm needs key size of 2048 bits, while Elliptic Curve Cryptography (ECC) needs key size of 224-255 bits. Another issue with most of the existing implementation of security models is storage of secret keys. Stored keys are often protected by poorly selected user passwords that can either be guessed or obtained through brute force attacks. This is a weak link in a security model and can potentially compromise the integrity of sensitive data. Combining biometrics with cryptography is seen as a possible solution. This paper suggests an enhanced security model of OTP system using ECC with finger-print biometric. This model also suggests more security with less key length and there is no need to store any private key anywhere. It focuses to create and share secret key without transmitting any private key so that no one could access the secret key except themselves.
机译:一次性密码(OTP)的安全性至关重要,因为当今大多数电子商务交易都是借助这种机制来执行的。 OTP用于抵抗重播攻击/窃听。重播攻击/窃听是对连接到Internet或Intranet的计算系统的一种攻击形式。为了达到112位的安全级别,RSA算法需要2048位的密钥大小,而椭圆曲线密码术(ECC)需要224-255位的密钥大小。大多数现有安全模型实现的另一个问题是密钥的存储。存储的密钥通常受到选择不当的用户密码的保护,这些密码可以通过蛮力攻击来猜测或获取。这是安全模型中的薄弱环节,并有可能损害敏感数据的完整性。将生物识别技术与密码学相结合被视为一种可能的解决方案。本文提出了一种带有指纹生物特征识别的ECC增强型OTP系统安全模型。该模型还建议使用较短的密钥长度来提高安全性,并且无需在任何地方存储任何私钥。它着重于创建和共享秘密密钥而不传输任何私钥,因此除了他们自己之外,没有人可以访问该秘密密钥。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号