• DocumentCode
    245842
  • Title

    Privacy Preserving Biometric-Based User Authentication Protocol Using Smart Cards

  • Author

    Minsu Park ; Hyunsung Kim ; Sung-Woon Lee

  • Author_Institution
    Dept. of Cyber Security, Kyungil Univ., Gyeongsan, South Korea
  • fYear
    2014
  • fDate
    19-21 Dec. 2014
  • Firstpage
    1541
  • Lastpage
    1544
  • Abstract
    How to provide both security and privacy in communication networks has been an important issue for ubiquitous computing. Especially, user authentication in the current IT services has become one of important security issues. However, the security weaknesses in the user authentication have been exposed seriously due to the careless secret related information management and the sophisticated attack techniques. Recently, an enhanced biometric-based user authentication protocol is proposed by An, which uses three factors, password, smart card and biometrics. However, this paper shows that An´s protocol has weaknesses in the password guessing attack and the lack of privacy support if an attacker could get user´s smart card, could read on it and could intercept session messages between user and server. Furthermore, this paper proposes a privacy preserving biometric-based user authentication protocol using smart card, which could solve the overall problems in An´s protocol and even put privacy considerations on it. The overall security analyses show that the proposed protocol achieves the desired security goals.
  • Keywords
    biometrics (access control); cryptographic protocols; data privacy; message authentication; smart cards; ubiquitous computing; An protocol; IT services; biometrics; communication network; enhanced biometric-based user authentication protocol; password guessing attack; privacy consideration; privacy preserving biometric-based user authentication protocol; privacy support; secret related information management; security weakness; smart cards; sophisticated attack technique; ubiquitous computing; Authentication; Biometrics (access control); Protocols; Servers; Silicon; Smart cards; Security; authentication; biometric-based; password; privacy;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computational Science and Engineering (CSE), 2014 IEEE 17th International Conference on
  • Conference_Location
    Chengdu
  • Print_ISBN
    978-1-4799-7980-6
  • Type

    conf

  • DOI
    10.1109/CSE.2014.285
  • Filename
    7023796