Protecting Biometrics Using Fuzzy Extractor and Non-invertible Transformation Methods in Kerberos Authentication Protocol
详细信息    查看全文
文摘
Kerberos is a distributed authentication protocol which guarantees the mutual authentication between client and server over an insecure network. After the identification, all the subsequent communications are encrypted by session keys to ensure privacy and data integrity. Nowadays, many traditional authentication systems have tried moved to biometric system for convenience. However, the security and privacy of these systems need to put on the table. In this paper, we have proposed an efficient hybrid approach for protecting biometrics in remote authentication protocol based on Kerberos scheme. This protocol is not only resistant against attacks on the insecure network such as man-in-the-middle attack, replay attack,… but also able to protect the biometrics for using fuzzy extractor and non-invertible transformation. These techniques conceal the user’s cancelable biometrics into the cryptographic key called biometric key. This key is used to verify a user in authentication phase. Therefore, there is no need to store users’ plaint biometrics in the database. Even if biometric key is revealed, it is impossible for an attack to infer the users’ biometrics for the high security of the fuzzy extractor scheme. Moreover, another remarkable contribution of this work is that a user can also change his biometric key without replacing his biometrics. The protocol supports multi-factor authentication to enhance security of the entire system.

© 2004-2018 中国地质图书馆版权所有 京ICP备05064691号 京公网安备11010802017129号

地址:北京市海淀区学院路29号 邮编:100083

电话:办公室:(+86 10)66554848;文献借阅、咨询服务、科技查新:66554700