首页> 外文期刊>Security and communication networks >A fingerprint based bio-cryptographic security protocol designed for client/server authentication in mobile computing environment
【24h】

A fingerprint based bio-cryptographic security protocol designed for client/server authentication in mobile computing environment

机译:基于指纹的生物密码安全协议,用于移动计算环境中的客户端/服务器身份验证

获取原文
获取原文并翻译 | 示例
           

摘要

With fast evolution of mobile devices and mobile network, the need of protecting user sensitive information locally and performing secure user authentication remotely become evermore increasing. Bio-cryptography is emerging as a powerful solution which can combine the advantages of conventional cryptography and biometric security. In this paper, we present an efficient bio-cryptographic security protocol designed for client/server authentication in current mobile computing environment, with a reasonable assumption that server is secure. In this protocol, fingerprint biometric is used in user verification, protected by a computationally efficient Public Key Infrastructure (PKI) scheme, Elliptic Curve Cryptography (ECC). The genuine fingerprint information is hidden in the feature vault which is the mixture of genuine and chaff features. Fingerprint features are not only used for biometric verification but also for cryptographic key generation. Our security analysis shows that the proposed protocol can provide a secure and trustworthy authentication of remote mobile users over insecure network. Experimental results on public domain database show an acceptable verification performance. We also tested the computational costs and efficiency of our protocol on the CLDC emulator using Java ME (previous J2ME) programming technology. The simulation results prove that the proposed protocol suits current mobile environment. Copyright © 2010 John Wiley & Sons, Ltd.
机译:随着移动设备和移动网络的快速发展,对本地保护用户敏感信息和远程执行安全用户身份验证的需求日益增长。生物密码学正在成为一种强大的解决方案,可以结合传统密码学和生物识别安全性的优点。在本文中,我们提出了一种有效的生物密码安全协议,该协议专为当前移动计算环境中的客户端/服务器身份验证而设计,并且可以合理地假设服务器是安全的。在此协议中,指纹生物识别技术用于用户验证,并受到计算效率高的公钥基础结构(PKI)方案椭圆曲线密码术(ECC)的保护。真实指纹信息隐藏在特征库中,该库是真实特征与谷壳特征的混合体。指纹功能不仅用于生物特征验证,而且还用于加密密钥生成。我们的安全性分析表明,所提出的协议可以通过不安全的网络为远程移动用户提供安全可靠的身份验证。在公共领域数据库上的实验结果显示了可接受的验证性能。我们还使用Java ME(以前的J2ME)编程技术在CLDC仿真器上测试了协议的计算成本和效率。仿真结果表明,该协议适合当前的移动环境。版权所有©2010 John Wiley&Sons,Ltd.

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号