• DocumentCode
    59074
  • Title

    Design and Analysis of a Highly User-Friendly, Secure, Privacy-Preserving, and Revocable Authentication Method

  • Author

    Yan Sui ; Xukai Zou ; Du, Eliza Y. ; Feng Li

  • Author_Institution
    Dept. of Comput. & Inf. Sci., Indiana Univ.-Purdue Univ. Indianapolis, Indianapolis, IN, USA
  • Volume
    63
  • Issue
    4
  • fYear
    2014
  • fDate
    Apr-14
  • Firstpage
    902
  • Lastpage
    916
  • Abstract
    A large portion of system breaches are caused by authentication failure, either during the login process or in the post-authentication session; these failures are themselves related to the limitations associated with existing authentication methods. Current authentication methods, whether proxy based or biometrics based, are not user-centric and/or endanger users´ (biometric) security and privacy. In this paper, we propose a biometrics based user-centric authentication approach. This method involves introducing a reference subject (RS), securely fusing the user´s biometrics with the RS, generating a BioCapsule (BC) from the fused biometrics, and employing BCs for authentication. Such an approach is user friendly, identity bearing yet privacy-preserving, resilient, and revocable once a BC is compromised. It also supports “one-click sign-on” across systems by fusing the user´s biometrics with a distinct RS on each system. Moreover, active and non-intrusive authentication can be automatically performed during post-authentication sessions. We formally prove that the secure fusion based approach is secure against various attacks. Extensive experiments and detailed comparison with existing approaches show that its performance (i.e., authentication accuracy) is comparable to existing typical biometric approaches and the new BC based approach also possesses many desirable features such as diversity and revocability.
  • Keywords
    biometrics (access control); data privacy; message authentication; sensor fusion; BC based approach; BioCapsule; RS; active authentication; authentication failure; biometrics based user centric authentication approach; login process; nonintrusive authentication; one click sign-on across systems; post authentication session; privacy preserving method; reference subject; revocable authentication method; secure fusion based approach; user biometrics fusion; Authentication; Feature extraction; Iris recognition; Measurement; Privacy; Authentication; BioCapsule (BC); biometric cryptosystem (BCS); cancelable biometrics (CB); privacy-preserving; secure fusion;
  • fLanguage
    English
  • Journal_Title
    Computers, IEEE Transactions on
  • Publisher
    ieee
  • ISSN
    0018-9340
  • Type

    jour

  • DOI
    10.1109/TC.2013.25
  • Filename
    6463410