A privacy-preserving multifactor authentication system

被引:12
|
作者
Acar, Abbas [1 ]
Liu, Wenyi [2 ]
Beyah, Raheem [2 ]
Akkaya, Kemal [1 ]
Uluagac, Arif Selcuk [1 ]
机构
[1] Florida Int Univ, Sch Elect & Comp Engn, Miami, FL 33172 USA
[2] Georgia Inst Technol, Sch Elect & Comp Engn, Atlanta, GA 30332 USA
来源
SECURITY AND PRIVACY | 2019年 / 2卷 / 05期
基金
美国国家科学基金会;
关键词
fuzzy hashing; homomorphic encryption; multifactor authentication; privacy-preserving; FULLY HOMOMORPHIC ENCRYPTION; SCHEME;
D O I
10.1002/spy2.88
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In recent years, there has been a significant number of works on the development of multifactor authentication (MFA) systems. Traditionally, behavioral biometrics (eg, keystroke dynamics) have been known to have the best usability because they do not require one to know or possess anything-they simply communicate "how you type" to an authenticator. However, though highly usable, MFA approaches that are based on biometrics are highly intrusive, and users' sensitive information is exposed to untrusted servers. To address this privacy concern, in this paper, we present a privacy-preserving MFA system for computer users, called PINTA. In PINTA, the second factor is a hybrid behavioral profile user, while the first authentication factor is a password. The hybrid profile of the user includes host-based and network flow-based features. Since the features include users' sensitive information, it needs to be protected from untrusted parties. To protect users' sensitive profiles and to handle the varying nature of the user profiles, we adopt two cryptographic methods: Fuzzy hashing and fully homomorphic encryption (FHE). Our results show that PINTA can successfully validate legitimate users and detect impostors. Although the results are promising, the trade-off for privacy preservation is a slight reduction in performance compared with traditional identity-based MFA techniques.
引用
收藏
页数:19
相关论文
共 50 条
  • [21] Privacy-Preserving Delegable Authentication in the Internet of Things
    Gritti, Clementine
    Onen, Melek
    Molva, Refik
    [J]. SAC '19: PROCEEDINGS OF THE 34TH ACM/SIGAPP SYMPOSIUM ON APPLIED COMPUTING, 2019, : 861 - 869
  • [22] Privacy-Preserving Biometric Authentication: Cryptanalysis and Countermeasures
    Zhang, Hui
    Li, Xuejun
    Tan, Syh-Yuan
    Lee, Ming Jie
    Jin, Zhe
    [J]. IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2023, 20 (06) : 5056 - 5069
  • [23] Privacy-Preserving Cryptocurrency With Threshold Authentication and Regulation
    Zhang, Zhao
    Xu, Chunxiang
    Han, Yunxia
    [J]. IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2024, 19 : 6620 - 6635
  • [24] Privacy-Preserving Graph Operations for Mobile Authentication
    Li, Peng
    Zhou, Fucai
    Xu, Zifeng
    Li, Yuxi
    Xu, Jian
    [J]. WIRELESS COMMUNICATIONS & MOBILE COMPUTING, 2020, 2020
  • [25] A Lightweight Privacy-Preserving Authentication Protocol for VANETs
    Li, Xiong
    Liu, Tian
    Obaidat, Mohammad S.
    Wu, Fan
    Vijayakumar, Pandi
    Kumar, Neeraj
    [J]. IEEE SYSTEMS JOURNAL, 2020, 14 (03): : 3547 - 3557
  • [26] A Generic Model for Privacy-Preserving Authentication on Smartphones
    Keykhaie, Sepehr
    Pierre, Samuel
    [J]. 2021 15TH ANNUAL IEEE INTERNATIONAL SYSTEMS CONFERENCE (SYSCON 2021), 2021,
  • [27] A privacy-preserving quantum authentication for vehicular communication
    Challagundla, Koushik
    Sutradhar, Kartick
    [J]. Quantum Information Processing, 2024, 23 (11)
  • [28] Distributed Aggregate Privacy-Preserving Authentication in VANETs
    Zhang, Lei
    Wu, Qianhong
    Domingo-Ferrer, Josep
    Qin, Bo
    Hu, Chuanyan
    [J]. IEEE TRANSACTIONS ON INTELLIGENT TRANSPORTATION SYSTEMS, 2017, 18 (03) : 516 - 526
  • [29] A novel privacy-preserving biometric authentication scheme
    Mao, Xuechun
    Chen, Ying
    Deng, Cong
    Zhou, Xiaqing
    [J]. PLOS ONE, 2023, 18 (05):
  • [30] Novel and Efficient Privacy-Preserving Continuous Authentication
    Baig, Ahmed Fraz
    Eskeland, Sigurd
    Yang, Bian
    [J]. CRYPTOGRAPHY, 2024, 8 (01)