Cloud Password Manager Using Privacy-Preserved Biometrics

Bian Yang, Huiguang Chu, Guoqiang Li, Slobodan V. Petrovic, C. Busch
{"title":"Cloud Password Manager Using Privacy-Preserved Biometrics","authors":"Bian Yang, Huiguang Chu, Guoqiang Li, Slobodan V. Petrovic, C. Busch","doi":"10.1109/IC2E.2014.91","DOIUrl":null,"url":null,"abstract":"Using one password for all web services is not secure because the leakage of the password compromises all the web services accounts, while using independent passwords for different web services is inconvenient for the identity claimant to memorize. A password manager is used to address this security-convenience dilemma by storing and retrieving multiple existing passwords using one master password. On the other hand, a password manager liberates human brain by enabling people to generate strong passwords without worry about memorizing them. While a password manager provides a convenient and secure way to managing multiple passwords, it centralizes the passwords storage and shifts the risk of passwords leakage from distributed service providers to a software or token authenticated by a single master password. Concerned about this one master password based security, biometrics could be used as a second factor for authentication by verifying the ownership of the master password. However, biometrics based authentication is more privacy concerned than a non-biometric password manager. In this paper we propose a cloud password manager scheme exploiting privacy enhanced biometrics, which achieves both security and convenience in a privacy-enhanced way. The proposed password manager scheme relies on a cloud service to synchronize all local password manager clients in an encrypted form, which is efficient to deploy the updates and secure against untrusted cloud service providers.","PeriodicalId":273902,"journal":{"name":"2014 IEEE International Conference on Cloud Engineering","volume":"17 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2014-03-11","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"12","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2014 IEEE International Conference on Cloud Engineering","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/IC2E.2014.91","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 12

Abstract

Using one password for all web services is not secure because the leakage of the password compromises all the web services accounts, while using independent passwords for different web services is inconvenient for the identity claimant to memorize. A password manager is used to address this security-convenience dilemma by storing and retrieving multiple existing passwords using one master password. On the other hand, a password manager liberates human brain by enabling people to generate strong passwords without worry about memorizing them. While a password manager provides a convenient and secure way to managing multiple passwords, it centralizes the passwords storage and shifts the risk of passwords leakage from distributed service providers to a software or token authenticated by a single master password. Concerned about this one master password based security, biometrics could be used as a second factor for authentication by verifying the ownership of the master password. However, biometrics based authentication is more privacy concerned than a non-biometric password manager. In this paper we propose a cloud password manager scheme exploiting privacy enhanced biometrics, which achieves both security and convenience in a privacy-enhanced way. The proposed password manager scheme relies on a cloud service to synchronize all local password manager clients in an encrypted form, which is efficient to deploy the updates and secure against untrusted cloud service providers.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
云密码管理使用隐私保护的生物识别技术
对所有web服务使用一个密码是不安全的,因为密码泄露会危及所有web服务帐户,而对不同的web服务使用独立的密码则不方便身份索赔者记忆。密码管理器通过使用一个主密码存储和检索多个现有密码来解决这种安全性-便利性难题。另一方面,密码管理器解放了人类的大脑,让人们不用担心记住它们,就能生成强密码。虽然密码管理器提供了一种方便和安全的方式来管理多个密码,但它集中了密码存储,并将密码泄露的风险从分布式服务提供商转移到由单个主密码验证的软件或令牌上。考虑到这种基于主密码的安全性,生物识别技术可以通过验证主密码的所有权来作为身份验证的第二个因素。然而,基于生物识别的身份验证比非生物识别密码管理器更关注隐私。本文提出了一种利用隐私增强生物识别技术的云密码管理方案,以增强隐私的方式实现了安全性和便利性。所提出的密码管理器方案依赖于云服务以加密形式同步所有本地密码管理器客户端,从而有效地部署更新并防止不受信任的云服务提供商。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Combining Declarative and Imperative Cloud Application Provisioning Based on TOSCA Splicing MPLS and OpenFlow Tunnels Based on SDN Paradigm CoMoT -- A Platform-as-a-Service for Elasticity in the Cloud A Verification Platform for SDN-Enabled Applications Extraction of Bridges from High Resolution Remote Sensing Image Based on Topology Modeling
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1