A privacy-preserving multifactor authentication system

被引:12
|
作者
Acar, Abbas [1 ]
Liu, Wenyi [2 ]
Beyah, Raheem [2 ]
Akkaya, Kemal [1 ]
Uluagac, Arif Selcuk [1 ]
机构
[1] Florida Int Univ, Sch Elect & Comp Engn, Miami, FL 33172 USA
[2] Georgia Inst Technol, Sch Elect & Comp Engn, Atlanta, GA 30332 USA
来源
SECURITY AND PRIVACY | 2019年 / 2卷 / 05期
基金
美国国家科学基金会;
关键词
fuzzy hashing; homomorphic encryption; multifactor authentication; privacy-preserving; FULLY HOMOMORPHIC ENCRYPTION; SCHEME;
D O I
10.1002/spy2.88
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In recent years, there has been a significant number of works on the development of multifactor authentication (MFA) systems. Traditionally, behavioral biometrics (eg, keystroke dynamics) have been known to have the best usability because they do not require one to know or possess anything-they simply communicate "how you type" to an authenticator. However, though highly usable, MFA approaches that are based on biometrics are highly intrusive, and users' sensitive information is exposed to untrusted servers. To address this privacy concern, in this paper, we present a privacy-preserving MFA system for computer users, called PINTA. In PINTA, the second factor is a hybrid behavioral profile user, while the first authentication factor is a password. The hybrid profile of the user includes host-based and network flow-based features. Since the features include users' sensitive information, it needs to be protected from untrusted parties. To protect users' sensitive profiles and to handle the varying nature of the user profiles, we adopt two cryptographic methods: Fuzzy hashing and fully homomorphic encryption (FHE). Our results show that PINTA can successfully validate legitimate users and detect impostors. Although the results are promising, the trade-off for privacy preservation is a slight reduction in performance compared with traditional identity-based MFA techniques.
引用
收藏
页数:19
相关论文
共 50 条
  • [41] A Privacy-Preserving Attribute-Based Authentication System for Mobile Health Networks
    Guo, Linke
    Zhang, Chi
    Sun, Jinyuan
    Fang, Yuguang
    [J]. IEEE TRANSACTIONS ON MOBILE COMPUTING, 2014, 13 (09) : 1927 - 1941
  • [42] Efficient Certificateless Conditional Privacy-Preserving Authentication for VANETs
    Zhou, Xiaotong
    Luo, Min
    Vijayakumar, Pandi
    Peng, Cong
    He, Debiao
    [J]. IEEE TRANSACTIONS ON VEHICULAR TECHNOLOGY, 2022, 71 (07) : 7863 - 7875
  • [43] A comprehensive survey on authentication and privacy-preserving schemes in VANETs
    Mundhe, Pravin
    Verma, Shekhar
    Venkatesan, S.
    [J]. COMPUTER SCIENCE REVIEW, 2021, 41
  • [44] Privacy-Preserving Authentication Systems Using Smart Devices
    Malina, Lukas
    Hajny, Jan
    Martinasek, Zdenek
    [J]. 2016 39TH INTERNATIONAL CONFERENCE ON TELECOMMUNICATIONS AND SIGNAL PROCESSING (TSP), 2016, : 11 - 14
  • [45] A Secure and Privacy-Preserving Mutual Authentication System for Global Roaming in Mobile Networks
    Shashidhara, R.
    Lajuvanthi, M.
    Akhila, S.
    [J]. ARABIAN JOURNAL FOR SCIENCE AND ENGINEERING, 2022, 47 (02) : 1435 - 1446
  • [46] PAAS: A Privacy-Preserving Attribute-based Authentication System for eHealth Networks
    Guo, Linke
    Zhang, Chi
    Sun, Jinyuan
    Fang, Yuguang
    [J]. 2012 IEEE 32ND INTERNATIONAL CONFERENCE ON DISTRIBUTED COMPUTING SYSTEMS (ICDCS), 2012, : 224 - 233
  • [47] Privacy-Preserving Smart Metering with Authentication in a Smart Grid
    Hur, Jun Beom
    Koo, Dong Young
    Shin, Young Joo
    [J]. APPLIED SCIENCES-BASEL, 2015, 5 (04): : 1503 - 1527
  • [48] A Privacy-Preserving Roaming Authentication Scheme for Ubiquitous Networks
    Zhou, You-sheng
    Zhou, Jun-feng
    Wang, Feng
    [J]. INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2016, 7 (01) : 463 - 471
  • [49] A Privacy-Preserving Authentication Scheme for a Blockchain-Based Energy Trading System
    Son, Seunghwan
    Oh, Jihyeon
    Kwon, Deokkyu
    Kim, Myeonghyun
    Park, Kisung
    Park, Youngho
    Lansky, Jan
    [J]. MATHEMATICS, 2023, 11 (22)
  • [50] A Secure and Privacy-Preserving Mutual Authentication System for Global Roaming in Mobile Networks
    R. Shashidhara
    M. Lajuvanthi
    S. Akhila
    [J]. Arabian Journal for Science and Engineering, 2022, 47 : 1435 - 1446