首页> 外文期刊>Future generation computer systems >Dynamic digest based authentication for client-server systems using biometric verification
【24h】

Dynamic digest based authentication for client-server systems using biometric verification

机译:使用生物识别的客户端服务器系统基于动态摘要的身份验证

获取原文
获取原文并翻译 | 示例

摘要

The client authentication is a significant process in clientserver systems. Such a process is highly secure when a client may be authenticated according to a set of unique verifiable data, i.e., biometric traits. However, biometric based systems with the low-cost, dense biometric sensors, and power of fast processing need a method of automatic client recognition for the robust client authentication. Such a method faces three challenges: (1) the effective recognition of the biometric patterns inputted to the system, (2) the provision of security to prevent the vulnerability of the system, and (3) the preparation of personal privacy. Many remote biometric authentication schemes have been developed to establish secure mutual communication between a client as a device node and server over an untrusted channel. By employing a secure remote biometric based authentication protocol, a client that acts in a node and a server that contains resources can authenticate each other in a secure and trustable manner. In our previous work, we proposed a digest based authentication method that preserves privacy of clients biometric templates and authenticates the client securely by generating non-deterministic semi-digest. By reviewing and cryptanalyzing this method, in the current paper, we focus on the improvement of the method for providing the invulnerability against user anonymity and server masquerading attacks. We show that our improved scheme is secure against the attacks and prove its functionality features. (C) 2019 Elsevier B.V. All rights reserved.
机译:客户端认证是客户端服务器系统中的重要过程。当可以根据一组唯一的可验证数据(即生物特征)对客户端进行身份验证时,此过程高度安全。但是,具有低成本,密集型生物特征传感器以及快速处理能力的基于生物特征的系统需要一种用于可靠的客户端身份验证的自动客户端识别方法。这种方法面临三个挑战:(1)有效识别输入到系统的生物特征码;(2)提供安全性以防止系统易受攻击;以及(3)准备个人隐私。已经开发了许多远程生物特征认证方案,以在作为设备节点的客户端和服务器之间通过不受信任的通道建立安全的相互通信。通过采用基于安全的远程生物统计的身份验证协议,充当节点的客户端和包含资源的服务器可以以安全和可信任的方式相互进行身份验证。在我们之前的工作中,我们提出了一种基于摘要的身份验证方法,该方法可保留客户端生物特征模板的隐私并通过生成不确定的半摘要来安全地对客户端进行身份验证。通过对这种方法进行回顾和加密分析,在当前的论文中,我们集中于提供针对用户匿名性和服务器伪装攻击的无害性方法的改进。我们证明了我们改进的方案可以抵御攻击,并证明其功能特性。 (C)2019 Elsevier B.V.保留所有权利。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号