...
首页> 外文期刊>Computers & Security >Reconciling user privacy and implicit authentication for mobile devices
【24h】

Reconciling user privacy and implicit authentication for mobile devices

机译:协调移动设备的用户隐私和隐式身份验证

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

In an implicit authentication system, a user profile is used as an additional factor to strengthen the authentication of mobile users. The profile consists of features that are constructed using the history of user actions on her mobile device over time. The profile is stored on the server and is used to authenticate an access request originated from the device at a later time. An access request will include a vector of recent measurements of the features on the device, that will be subsequently matched against the features stored at the server, to accept or reject the request. The features however include private information such as user location or web sites that have been visited. We propose a privacy-preserving implicit authentication system that achieves implicit authentication without revealing information about the usage profiles of the users to the server. We propose an architecture, give a formal security model and a construction with provable security in two settings where: (ⅰ) the device follows the protocol, and (ⅱ) the device is captured and behaves maliciously.
机译:在隐式身份验证系统中,用户配置文件用作增强移动用户身份验证的附加因素。该配置文件由功能组成,这些功能是使用一段时间内其移动设备上的用户操作历史记录来构建的。该配置文件存储在服务器上,用于在以后验证来自设备的访问请求。访问请求将包含设备上功能最近测量的向量,随后将与存储在服务器上的功能进行匹配,以接受或拒绝该请求。但是,这些功能包括私人信息,例如已访问的用户位置或网站。我们提出了一种隐私保护的隐式身份验证系统,该系统可实现隐式身份验证,而不会向服务器泄露有关用户使用情况的信息。我们提出一种体系结构,在两种情况下给出正式的安全模型和具有可证明的安全性的构造,其中:(ⅰ)设备遵循协议,并且(ⅱ)设备被捕获并具有恶意行为。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号