DocumentCode :
723355
Title :
Enhancing OAuth services security by an authentication service with face recognition
Author :
Alotaibi, Aziz ; Mahmmod, Ausif
Author_Institution :
Univ. of Bridgeport, Bridgeport, CT, USA
fYear :
2015
fDate :
1-1 May 2015
Firstpage :
1
Lastpage :
6
Abstract :
Controlling secure access to web Application Programming Interfaces (APIs) and web services has become more vital with advancement and use of the web technologies. The security of web services APIs is encountering critical issues in managing authenticated and authorized identities of users. Open Authorization (OAuth) is a secure protocol that allows the resource owner to grant permission to a third-party application in order to access the resource owner´s protected resource on their behalf, without releasing their credentials. Most web APIs are still using the traditional authentication which is vulnerable to many attacks such as man-in-the middle attack. To reduce such vulnerability, we enhance the security of OAuth through the implementation of a biometric service. We introduce a face verification system based on Local Binary Patterns as an authentication service handled by the authorization server. The entire authentication process consists of three services: Image registration service, verification service, and access token service. The developed system is most useful in securing those services where a human identification is required.
Keywords :
Web services; application program interfaces; authorisation; biometrics (access control); face recognition; image registration; OAuth service security; Web application programming interfaces; Web services API; Web technologies; access token service; authentication service; authorization server; biometric service; face recognition; face verification system; human identification; image registration service; local binary patterns; open authorization; resource owner protected resource; third-party application; verification service; Authentication; Authorization; Databases; Protocols; Servers; Web services; Access Token; Face Recognition; OAuth; Open Authorization; Web API; Web Services;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Systems, Applications and Technology Conference (LISAT), 2015 IEEE Long Island
Conference_Location :
Farmingdale, NY
Type :
conf
DOI :
10.1109/LISAT.2015.7160208
Filename :
7160208
Link To Document :
بازگشت