WebID + biometrics with permuted disposable features

WebID + biometrics with permuted disposable features
复制标题

DOI:
10.1145/3476883.3524050
复制
发表时间:
2022-04
期刊:
Proceedings of the 2022 ACM Southeast Conference
影响因子:
--
通讯作者:
Takiva Richardson;Joseph Shelton;Yasmin Eady;K. Kyei;A. Esterline
Takiva Richardson;Joseph Shelton;Yasmin Eady;K. Kyei;A. Esterline
中科院分区:
其他
文献类型:
--
作者:
Takiva Richardson;Joseph Shelton;Yasmin Eady;K. Kyei;A. Esterline

文献摘要

相似文献

对于网络通信,网络安全和身份验证是关键组成部分。这项工作涉及的安全性和身份验证问题,因为它涉及到语义Web的功能。“语义网”一词暗指万维网联盟的标准思想,使互联网数据机器可读和可重用。例如,WebID是一种用于管理与自定义位置处的人员和服务相关联的配置文件数据的技术。虽然WebID协议本身允许用户更多地控制他们与在线服务的连接,但生物特征认证是一个额外的过程,可以为个人增加安全性和便利性。具有生物特征认证的WebID协议允许对个人用户进行更多控制,但网络连接仍然容易受到重放攻击(网络受到破坏,身份验证信息被捕获并重放以允许未经授权的访问)。对生物特征认证系统的重放攻击尤其具有破坏性,因为生物特征比密码更难更改。先前的工作已经完成,以开发一个人的生物特征的唯一和准确的表示,使得如果不良行为者捕获任何认证生物特征数据,则其在重放攻击中将是无用的,因为系统在每次访问尝试之后使用生物特征的新表示。在本文中,我们建议扩展以前的工作,以增加与WebID标识符相结合的唯一和可靠的数据表示的数量。本文将概述目前正在开发的系统以及其他WebID组件。
For networked communications, cyber security and authentication are critical components. This work deals with the issue of security and authentication as it relates to features of the Semantic Web. The phrase "Semantic Web" alludes to the World Wide Web Consortium's idea of standards to make internet data machine-readable and reusable. WebID, for example, is a technique for managing profile data connected with people and services at self-defined locations. While the WebID protocol alone allows users more control over their connections to online services, biometric authentication is an additional process that can add security and convenience for individuals. The WebID protocol with biometric authentication allows more control for the individual user, but networked connections are still vulnerable to replay attacks (an attack in which the network is compromised and authenticating information is captured and replayed to allow unauthorized access). Replay attacks on a biometrics authentication system are particularly damaging since biometrics are more difficult to change than passwords. Prior work has been done to develop unique and accurate representations of one's biometric, such that if a bad actor captures any authenticating biometric data, it will not be useful in a replay attack as the system uses a new representation of biometrics after each access attempt. In this paper, we suggest extending previous work to increase the number of unique and reliable data representations in conjunction with WebID identifiers. This paper will provide an overview of the system that is currently under development, as well as additional WebID components.