• DocumentCode
    244186
  • Title

    Cloud Password Manager Using Privacy-Preserved Biometrics

  • Author

    Bian Yang ; Huiguang Chu ; Guoqiang Li ; Petrovic, Slobodan ; Busch, Christoph

  • Author_Institution
    Norwegian Inf. Security Lab., Gjovik Univ. Coll., Gjovik, Norway
  • fYear
    2014
  • fDate
    11-14 March 2014
  • Firstpage
    505
  • Lastpage
    509
  • Abstract
    Using one password for all web services is not secure because the leakage of the password compromises all the web services accounts, while using independent passwords for different web services is inconvenient for the identity claimant to memorize. A password manager is used to address this security-convenience dilemma by storing and retrieving multiple existing passwords using one master password. On the other hand, a password manager liberates human brain by enabling people to generate strong passwords without worry about memorizing them. While a password manager provides a convenient and secure way to managing multiple passwords, it centralizes the passwords storage and shifts the risk of passwords leakage from distributed service providers to a software or token authenticated by a single master password. Concerned about this one master password based security, biometrics could be used as a second factor for authentication by verifying the ownership of the master password. However, biometrics based authentication is more privacy concerned than a non-biometric password manager. In this paper we propose a cloud password manager scheme exploiting privacy enhanced biometrics, which achieves both security and convenience in a privacy-enhanced way. The proposed password manager scheme relies on a cloud service to synchronize all local password manager clients in an encrypted form, which is efficient to deploy the updates and secure against untrusted cloud service providers.
  • Keywords
    Web services; authorisation; biometrics (access control); cloud computing; data privacy; trusted computing; Web service account; biometrics based authentication; cloud password manager; distributed service providers; local password manager client synchronization; master password based security; nonbiometric password manager; password leakage risk; password storage; privacy enhanced biometrics; privacy-preserved biometrics; token authentication; untrusted cloud service providers; Authentication; Biometrics (access control); Cryptography; Privacy; Synchronization; Web services; biometrics; cloud; password manager; privacy preservation; security;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Cloud Engineering (IC2E), 2014 IEEE International Conference on
  • Conference_Location
    Boston, MA
  • Type

    conf

  • DOI
    10.1109/IC2E.2014.91
  • Filename
    6903519