Efficient Mobile User Authentication Service with Privacy Preservation and User Untraceability

An Braeken, A. Touhafi
{"title":"Efficient Mobile User Authentication Service with Privacy Preservation and User Untraceability","authors":"An Braeken, A. Touhafi","doi":"10.1109/CloudTech49835.2020.9365896","DOIUrl":null,"url":null,"abstract":"Security questions and answers for authentication are a common approach to enable the user to reset forgotten passwords. Moreover, they are also sometimes used as alternative for the classical username-password system, which fails in offering a good balance between user friendliness and security as long and complex passwords are required. However, in order to guarantee the privacy of the user as imposed by the new General Data Protection Regulation (GDPR), it should be impossible to derive the answer of the user by any other entity, including the server provider or the server managing the authentication.In this paper, we present an efficient mobile based security mechanism to realise this goal. The proposed scheme can be applied on top of any type of question-answer based authentication system. In addition, our solution also offers anonymity and untraceability of the user, such that no activity patterns can be drawn by simply eavesdropping on the communication channel to the service provider or the authentication server. We show that our proposed mechanism not only offers more security features compared to related work, but it is also significantly faster, in particular at the side of the user.","PeriodicalId":272860,"journal":{"name":"2020 5th International Conference on Cloud Computing and Artificial Intelligence: Technologies and Applications (CloudTech)","volume":"108 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2020-11-24","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2020 5th International Conference on Cloud Computing and Artificial Intelligence: Technologies and Applications (CloudTech)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/CloudTech49835.2020.9365896","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

Security questions and answers for authentication are a common approach to enable the user to reset forgotten passwords. Moreover, they are also sometimes used as alternative for the classical username-password system, which fails in offering a good balance between user friendliness and security as long and complex passwords are required. However, in order to guarantee the privacy of the user as imposed by the new General Data Protection Regulation (GDPR), it should be impossible to derive the answer of the user by any other entity, including the server provider or the server managing the authentication.In this paper, we present an efficient mobile based security mechanism to realise this goal. The proposed scheme can be applied on top of any type of question-answer based authentication system. In addition, our solution also offers anonymity and untraceability of the user, such that no activity patterns can be drawn by simply eavesdropping on the communication channel to the service provider or the authentication server. We show that our proposed mechanism not only offers more security features compared to related work, but it is also significantly faster, in particular at the side of the user.
具有隐私保护和用户不可追溯性的高效移动用户认证服务
身份验证的安全问题和答案是使用户能够重置忘记的密码的常用方法。此外,它们有时也被用作传统的用户名-密码系统的替代方案,由于需要长而复杂的密码,传统的用户名-密码系统无法在用户友好性和安全性之间提供良好的平衡。然而,为了保证新通用数据保护条例(GDPR)规定的用户隐私,任何其他实体(包括服务器提供商或管理身份验证的服务器)都不可能获得用户的答案。在本文中,我们提出了一种高效的基于移动的安全机制来实现这一目标。该方案可以应用于任何类型的基于问答的认证系统。此外,我们的解决方案还提供了用户的匿名性和不可追溯性,这样就不能通过简单地窃听到服务提供者或身份验证服务器的通信通道来绘制任何活动模式。我们表明,与相关工作相比,我们提出的机制不仅提供了更多的安全功能,而且速度也快得多,特别是在用户方面。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信