Preventing identity theft with electronic identity cards and the trusted platform module

A. Klenk, Holger Kinkelin, Christoph Eunicke, G. Carle
{"title":"Preventing identity theft with electronic identity cards and the trusted platform module","authors":"A. Klenk, Holger Kinkelin, Christoph Eunicke, G. Carle","doi":"10.1145/1519144.1519151","DOIUrl":null,"url":null,"abstract":"Together with the rapidly growing number of services in the Internet, authentication becomes an issue of increasing importance. A very common situation is that for each service, users must remember the associated name and password they are registered under. This method is prone to identity theft and its usability leaves much to be desired. The Trusted Platform Module (TPM) is a microcontroller with cryptographic functions that is integrated into many computers. It is capable to protect against software attacks. TPM can generate and store non-migratable keying material for authentication and is an effective safeguard against the acquisition and use of an identity by an adversary. Even though TPM prohibits identity theft, Internet services still have few options to verify the true identity of a user. Electronic identity cards (eID) assert for the identity of their owner. Their large-scale deployment can be expected in the near future. The use of eIDs is impaired, though. They must be present for each authentication, and all devices must be equipped with a compatible card reader. We mitigate the problems of both approaches by using eIDs for establishing trust in user specific TPM authentication credentials. The eID and a compatible reader must be present only at one time for establishing the initial trust. We integrated our identity theft resistant authentication method with the OpenID identity system to allow a large number of services to profit from verified and trustworthy identity assertions.","PeriodicalId":302603,"journal":{"name":"European Workshop on System Security","volume":"23 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2009-03-31","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"16","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"European Workshop on System Security","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/1519144.1519151","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 16

Abstract

Together with the rapidly growing number of services in the Internet, authentication becomes an issue of increasing importance. A very common situation is that for each service, users must remember the associated name and password they are registered under. This method is prone to identity theft and its usability leaves much to be desired. The Trusted Platform Module (TPM) is a microcontroller with cryptographic functions that is integrated into many computers. It is capable to protect against software attacks. TPM can generate and store non-migratable keying material for authentication and is an effective safeguard against the acquisition and use of an identity by an adversary. Even though TPM prohibits identity theft, Internet services still have few options to verify the true identity of a user. Electronic identity cards (eID) assert for the identity of their owner. Their large-scale deployment can be expected in the near future. The use of eIDs is impaired, though. They must be present for each authentication, and all devices must be equipped with a compatible card reader. We mitigate the problems of both approaches by using eIDs for establishing trust in user specific TPM authentication credentials. The eID and a compatible reader must be present only at one time for establishing the initial trust. We integrated our identity theft resistant authentication method with the OpenID identity system to allow a large number of services to profit from verified and trustworthy identity assertions.
通过电子身份证和可信平台模块防止身份盗窃
随着Internet上服务数量的快速增长,身份验证成为一个越来越重要的问题。一种非常常见的情况是,对于每个服务,用户必须记住他们注册时使用的相关名称和密码。这种方法容易导致身份被盗,其可用性也有待改进。可信平台模块(TPM)是集成在许多计算机中的具有加密功能的微控制器。它能够防止软件攻击。TPM可以生成和存储用于身份验证的不可迁移的密钥材料,并且是防止攻击者获取和使用身份的有效保障。尽管TPM禁止身份盗窃,互联网服务仍然没有多少选择来验证用户的真实身份。电子身份证(eID)声明其所有者的身份。它们的大规模部署有望在不久的将来实现。不过,eid的使用受到了损害。每次身份验证时都必须使用它们,并且所有设备都必须配备兼容的读卡器。我们通过使用eid在用户特定的TPM身份验证凭证中建立信任来缓解这两种方法的问题。为了建立初始信任,eID和兼容的读取器必须同时存在。我们将我们的防身份盗窃认证方法与OpenID身份系统集成在一起,允许大量的服务从经过验证和可信的身份断言中获利。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信