A Generic Framework for Three-Factor Authentication: Preserving Security and Privacy in Distributed Systems

A Generic Framework for Three-Factor Authentication: Preserving Security and Privacy in Distributed Systems
复制标题

DOI:
10.1109/tpds.2010.206
复制
发表时间:
2011-08-01
影响因子:
5.3
通讯作者:
Deng, Robert H.
Deng, Robert H.
中科院分区:
计算机科学2区
文献类型:
--
作者:
Huang, Xinyi;Xiang, Yang;Deng, Robert H.

文献摘要

被引文献

相似文献

作为分布式系统内安全性的一部分,需要保护各种服务和资源,防止未经授权的使用。远程身份验证是确定远程客户端身份的最常用方法。本文研究了一种基于密码、智能卡和生物特征三要素的系统客户端身份验证方法。提出了一种通用的安全框架,将双因素认证升级为三因素认证。这种转换不仅以较低的成本显著提高了信息保障,而且还保护了分布式系统中的客户端隐私。此外,我们的框架保留了底层双因素身份验证的几个实践友好的属性,我们认为这是独立的兴趣。
As part of the security within distributed systems, various services and resources need protection from unauthorized use. Remote authentication is the most commonly used method to determine the identity of a remote client. This paper investigates a systematic approach for authenticating clients by three factors, namely password, smart card, and biometrics. A generic and secure framework is proposed to upgrade two-factor authentication to three-factor authentication. The conversion not only significantly improves the information assurance at low cost but also protects client privacy in distributed systems. In addition, our framework retains several practice-friendly properties of the underlying two-factor authentication, which we believe is of independent interest.