UFace: Your universal password that no one can see
Autor: | Jianping Fan, Dan Lin, Nicholas Hilbert, Wei Jiang, Christian Storer |
---|---|
Rok vydání: | 2018 |
Předmět: |
Password
021110 strategic defence & security studies Authentication General Computer Science Computer science 0211 other engineering and technologies 020206 networking & telecommunications Plaintext 02 engineering and technology Multi-factor authentication Computer security computer.software_genre Chip Authentication Program ComputingMilieux_MANAGEMENTOFCOMPUTINGANDINFORMATIONSYSTEMS Generic Bootstrapping Architecture Authentication protocol Lightweight Extensible Authentication Protocol 0202 electrical engineering electronic engineering information engineering Challenge–response authentication Law computer Data Authentication Algorithm |
Zdroj: | Computers & Security. 77:627-641 |
ISSN: | 0167-4048 |
DOI: | 10.1016/j.cose.2017.09.016 |
Popis: | Due to the ease of use, face authentication could be a promising way to replace hard-to-remember passwords to access web services. However, to make face authentication suitable for web services, there are still several critical security and privacy challenges unaddressed. First, the existing authentication servers typically collect the plaintext of users' facial images in order to conduct authentication. If the servers are compromised, the attackers would obtain the users' facial images and can easily impersonate the users in any other applications that use face authentication. Second, it is also hard to prevent attackers from using facial images published in social network sites to impersonate the true user. In this paper, we conquered these two issues by proposing a novel secure face authentication system, called UFace. UFace uses special close-up facial images (which cannot be found online) for authentication. To further ensure the confidentiality of these close-up images, UFace guarantees that these images are only stored at user side and the servers have not any plaintext of these images. The face authentication is conducted securely with two collaborative authentication servers. UFace was implemented through both an Android application and multiple server side programs which were then evaluated in a real setting. The experimental results demonstrate that the UFace system can accurately authenticate users within a few seconds. |
Databáze: | OpenAIRE |
Externí odkaz: |