首页> 外文OA文献 >Revocable, Interoperable and User-Centric (Active) Authentication Across Cyberspace
【2h】

Revocable, Interoperable and User-Centric (Active) Authentication Across Cyberspace

机译:跨网络空间的可撤销,互操作性和以用户为中心的(主动)身份验证

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

This work addresses fundamental and challenging user authentication and universal identity issues and solves the problems of system usability, authentication data security, user privacy, irrevocability, interoperability, cross-matching attacks, and post-login authentication breaches associated with existing authentication systems. It developed a solid user-centric biometrics based authentication model, called Bio-Capsule (BC), and implemented an (active) authentication system. BC is the template derived from the (secure) fusion of a user’s biometrics and that of a Reference Subject (RS). RS is simply a physical object such as a doll or an artificial one, such as an image. It is users’ BCs, rather than original biometric templates, that are utilized for user authentication and identification. The implemented (active) authentication system will facilitate and safely protect individuals’ diffused cyber activities, which is particularly important nowadays, when people are immersed in cyberspace.User authentication is the first guard of any trustworthy computing system. Along with people’s immersion in the penetrated cyber space integrated with information, networked systems, applications and mobility, universal identity security& management and active authentication become of paramount importance for cyber security and user privacy. Each of three typical existing authentication methods, what you KNOW (Password/PIN), HAVE (SmartCard), and ARE (Fingerprint/Face/Iris) and their combinations, suffer from their own inherent problems. For example, biometrics is becoming a promising authentication/identification method because it binds an individual with his identity, is resistant to losses, and does not need to memorize/carry. However, biometrics introduces its own challenges. One serious problem with biometrics is that biometric templates are hard to be replaced once compromised. In addition, biometrics may disclose user’s sensitive information (such as race, gender, even health condition), thus creating user privacy concerns. In the recent years, there has been intensive research addressing biometric template security and replaceability, such as cancelable biometrics and Biometric Cryptosystems. Unfortunately, these approaches do not fully exploit biometric advantages (e.g., requiring a PIN), reduce authentication accuracy, and/or suffer from possible attacks. The proposed approach is the first elegant solution to effectively address irreplaceability, privacy-preserving, and interoperability of both login and after-login authentication. Our methodology preserves biometrics’ robustness and accuracy, without sacrificing system acceptability for the same user, and distinguishability between different users. Biometric features cannot be recovered from the user’s Biometric Capsule or Reference Subject, even when both are stolen. The proposed model can be applied at the signal, feature, or template levels, and facilitates integration with new biometric identification methods to further enhance authentication performance. Moreover, the proposed active, non-intrusive authentication is not only scalable, but also particularly suitable to emerging portable, mobile computing devices. In summary, the proposed approach is (i) usercentric, i.e., highly user friendly without additional burden on users, (ii) provably secure and resistant to attacks including cross-matching attacks, (iii) identity-bearing and privacy-preserving, (iv) replaceable, once Biometric Capsule is compromised, (v) scalable and highly adaptable, (vi) interoperable and single signing on across systems, and (vii) cost-effective and easy to use.
机译:这项工作解决了基本且具有挑战性的用户身份验证和通用标识问题,并解决了与现有身份验证系统相关的系统可用性,身份验证数据安全性,用户隐私,不可撤销性,互操作性,交叉匹配攻击以及登录后身份验证违规的问题。它开发了一种以用户为中心的,基于生物特征的可靠身份验证模型,称为生物胶囊(BC),并实现了(主动)身份验证系统。 BC是从用户生物特征数据与参考对象(RS)的(安全)融合中获得的模板。 RS只是一个物理对象(例如娃娃)或人造对象(例如图像)。用于用户身份验证和识别的是用户的BC,而不是原始的生物统计模板。已实施的(主动)身份验证系统将促进并安全地保护个人分散的网络活动,这在当今人们沉浸在网络空间中时尤其重要。用户身份验证是任何可信赖计算系统的第一道防线。随着人们沉浸在与信息,网络系统,应用程序和移动性集成在一起的渗透的网络空间中,通用身份安全和管理以及主动身份验证对于网络安全和用户隐私至关重要。现有的三种典型的身份验证方法,即您所知道的(密码/ PIN),HAVE(智能卡)和ARE(指纹/面部/虹膜)及其组合,都存在各自固有的问题。例如,生物识别技术正成为一种很有前途的身份验证/识别方法,因为它可以将个人与其身份绑定在一起,可以抵抗损失,并且不需要记忆/携带。但是,生物识别技术带来了自己的挑战。生物识别技术的一个严重问题是,一旦遭到破坏,生物识别模板就很难更换。此外,生物识别技术可能会泄露用户的敏感信息(例如种族,性别,甚至健康状况),从而引起用户隐私隐患。近年来,针对可生物识别模板的安全性和可替换性进行了深入研究,例如可取消的生物识别和生物识别密码系统。不幸的是,这些方法没有充分利用生物统计的优点(例如,需要PIN),降低认证准确性和/或遭受可能的攻击。所提出的方法是第一个优雅的解决方案,可以有效解决登录身份验证和登录后身份验证的不可替代性,隐私保护和互操作性。我们的方法保持了生物识别技术的鲁棒性和准确性,而不会牺牲同一用户的系统可接受性以及不同用户之间的可区分性。即使用户的生物特征胶囊或参考对象被盗,也无法恢复其生物特征。所提出的模型可以应用于信号,特征或模板级别,并有助于与新的生物识别方法集成,从而进一步增强身份验证性能。而且,提出的主动,非侵入式认证不仅是可扩展的,而且还特别适合于新兴的便携式移动计算设备。总而言之,建议的方法是(i)以用户为中心,即高度用户友好,而不会给用户带来额外负担;(ii)可证明的安全性和抵抗性,包括交叉匹配攻击,(iii)带有身份和隐私保护, iv)一旦生物识别胶囊遭到破坏,就可以更换;(v)可扩展性和高度适应性;(vi)跨系统的互操作性和单一签名;以及(vii)具有成本效益且易于使用。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号