The Experts below are selected from a list of 270 Experts worldwide ranked by ideXlab platform
P. S. Aithal - One of the best experts on this subject based on the ideXlab platform.
-
a comparative study on fingerprint hash code otp and password based Multifactor Authentication model with an ideal system and existing systems
Social Science Research Network, 2018Co-Authors: Krishna Prasad K, P. S. AithalAbstract:Authentication is the process to validate the user identity and to grant some resources or services to the user. Authentication process uses many factors like password, biometrics, or One Time Password. Multifactor Authentication model always gives higher security than single-factor Authentication model. Fingerprint Hash code is not used for full security or Authentication purpose but it can be combined with other security elements like password or OTP in order to enhance security. Fingerprint Hash code acts as a key, which can uniquely identify every person. So it can be replaceable with user-id or username and can work along with text-based or picture based or pattern based passwords. In this paper based on focus group interaction, first, we define an Ideal Authentication System. The Ideal Authentication System used in this study consists of different components like Ideal Security, Ideal User-Friendly, Ideal Input, Ideal Process, and Ideal Performance Evaluation Matrices. In this paper, we also compare new Multifactor Authentication Model based on Fingerprint Hash code, OTP, and Password with existing Authentication systems. The traditional user-id, password-based internet/mobile banking system, Apple iPhone X face recognition system, HDFC OTP Checkout for online transactions and Indian Aadhaar card registration process are the different existing systems used in this study to compare with the new model.
-
A STUDY ON Multifactor Authentication MODEL USING FINGERPRINT HASH CODE, PASSWORD AND OTP
2018Co-Authors: Krishna K. Prasad, P. S. AithalAbstract:By definition, Authentication is using one or multiple mechanisms to show that you are who you claim to be. As soon as the identity of the human or machine is demonstrated, then human or machine is authorized to grant some services. The modern research study reveals that fingerprint is not so secured like secured a password which consists of alphanumeric characters, number and special characters. Fingerprints are left at crime places, on materials or at the door which is usually class of latent fingerprints. We cannot keep fingerprint as secure like rigid passwords. Using some modern technology with copper and graphite spray it's easy to mimic fingerprint image. Fingerprints are a half-secret if passwords are leaked or hacked, it easily revocable using another password. But in a biometric security system, which uses only biometric features, is not easy to change fingerprint key or fingerprint are static biometric, which never change much throughout the lifespan. Fingerprints are left at car, door or anyplace where every person goes and places his finger. Fingerprint Hash code is not used for full security or Authentication purpose but it can be combined with other security elements like password or OTP in order to enhance security. In this paper, a novel method for Authentication is proposed by making use of Fingerprint Hash Code, Password, and OTP. In this study, we make use of Euclidean Distance to generate fingerprint Hash Code. Fingerprint Hash code is generated using MD5 Hash Function. The Model is implemented using MATLAB2015a. This paper also analyzes novel Authentication model used in this study with the aid of ABCD analysis
-
ABCD Analysis of Fingerprint Hash Code, Password and OTP based Multifactor Authentication Model
2018Co-Authors: P. S. Aithal, Krishna PrasadAbstract:Authentication is the usage of one or multiple mechanisms to show that who you declare or claim to be. Authentication ensures that users are granted to some resources or services after verifying their identity. The essential characteristics of every Authentication system are to provide high security for their users. Multifactor Authentication model always improves or enhances the security compared to single-factor Authentication model. This new model makes use of three factors-biometric Fingerprint Hash code, One Time Password (OTP), and Password. Fingerprints are not fully secret compare to passwords, because if passwords are leaked which can be easily revocable using another password and which is not true in case of fingerprint biometric security system. If an Authentication system uses only fingerprint biometric features, it is not easy to change fingerprint, because fingerprint is static biometric, which never change much throughout the lifespan. In this paper, as per ABCD analysis various determinant issues related to Multifactor Authentication Model for Verification/Authentication purpose are: (1) Security issues, (2) User-friendly issues, (3) Input issues, (4) Process issues, (5) Customer Issues, (6) Service Provider issues, and (5) Performance Evaluation matrix issues. The constituent critical elements of Multifactor Authentication model determinant issues are listed under the four constructs - advantages, benefits, constraints and disadvantages of the ABCD technique and tabulated. The analysis has brought out many critical constituent elements, which is one of the proofs for the success of the new methodology
Maha M Althobaiti - One of the best experts on this subject based on the ideXlab platform.
-
usable security of Authentication process new approach and practical assessment
International Conference for Internet Technology and Secured Transactions, 2015Co-Authors: Maha M Althobaiti, Pam J MayhewAbstract:Authentication mechanisms are considered the typical method to secure financial websites. Context Authentication has become increasingly important in the arena of online banking, which involves sensitive data that belong to users who trust their banks. Multifactor Authentication is the most commonly used method of strengthening the log-in process in e-banking. Developing a usable and secure Authentication approach and method is the most challenging area for researchers in the fields of security and Human-Computer Interaction (HCI). This paper describes a work-in-progress towards a new approach for authenticating users when access online banking by giving them the opportunity to choose their preferred method to log into e-banking. In our complex experiment with 100 online banking customers, we simulate an original online banking platform based on the proposed approach; then, we evaluate the usability and security of three different methods and assess user awareness of the most visible security design flaws. The initial result shows that the new system model was able to assess the usability and security of different Multifactor Authentication methods and it is considered a first attempt towards a usable and secure Authentication approach.
-
assessing usable security of Multifactor Authentication
Journal of Internet Technology and Secured Transaction, 2015Co-Authors: Maha M AlthobaitiAbstract:An Authentication mechanism is a security service that establishes the difference between authorised and unauthorised users. When used as part of certain website processes such as online banking, it provides users with greater safety and protection against service attacks and intruders. For an e-banking website to be considered effective, it should provide a usable and secure Authentication mechanism. Despite existing research on usability and security domains, there is a lack of research on synthesising the contributions of usable security and evaluating Multifactor Authentication methods. Without understanding the usability and security of Authentication mechanisms, the authenticating process is likely to become cumbersome and insecure. This negatively affects a goal of the Authentication process, convenience for the user. This thesis sought to investigate the usability and security of Multifactor Authentication and filled an important gap in the development of authenticating processes. It concentrated on users’ perspectives, which are crucial for the deployment of an authenticating process. To achieve the thesis goal, a systematic series of three studies has been conducted. First, an exploratory study was used to investigate the current state of the art of using Multifactor Authentication and to evaluate the usability and security of these methods. The study involved a survey of 614 e-banking users, who were selected because they were likely long-term users of online banking and they had two different bank accounts, a Saudi account and a foreign account (most foreign accounts were British). The study indicated that Multifactor Authentication has been widely adopted in e-banking in Saudi Arabia and the United Kingdom, with high levels of security and trustworthiness as compared to single factor Authentication. The second study was a descriptive study of the most common Authentication methods. This study aimed to learn more about commonly used methods that were identified in the previous study and sought to propose an appropriate combination of Authentication methods to be evaluated in the third study. The third study was an experimental study with 100 users to evaluate the usable security of three different Multifactor Authentication methods: finger print, secure device and card reader. A web based system was designed specifically for this study to simulate an original UK e-banking website. One of the main contribution of this study was that the system allowed users to choose their preferred Authentication method. Moreover, the study contributed to the field of usable security by proposing security evaluation criteria based on users’ awareness of security warnings. The key result obtained indicated that fingerprinting was the most usable and secure method. Additionally, the users’ level of understanding security warnings was very low, as shown by their reaction to the security indicators presented during the experiment.
-
security and usability of authenticating process of online banking user experience study
International Carnahan Conference on Security Technology, 2014Co-Authors: Maha M Althobaiti, Pam J MayhewAbstract:Bank websites are secure websites considered high risk, so security is a prime concern. Authentication is extremely important because it serves as the entry point for customers to access their personal and sensitive information. To be considered effective and desirable, a banking website should provide its users with secure and usable Authentication mechanisms. Otherwise, the Authentication process likely will become unsafe and frustrating for users. This issue in turn compromises the bank’s objective to make online transactions convenient for its users. Focusing on this dilemma, this paper sought to examine the security and usability of single and Multifactor Authentication methods, which are used by most banks to strengthen the security process. However, the security and usability of Multifactor Authentication have not been closely investigated from the user’s perspective. In a survey of 302 e-banking customers who owned at least two international bank accounts, Multifactor Authentication methods were perceived as secure and trustworthy, with a high rate of usability. Token-based Authentication was perceived as more usable than SMS-based Authentication, during which a SMS is sent via mobile means.
Mirosław Kurkowski - One of the best experts on this subject based on the ideXlab platform.
-
Multifactor Authentication Protocol in a Mobile Environment
IEEE Access, 2019Co-Authors: Bartłomiejczyk Maciej, El Fray Imed, Mirosław KurkowskiAbstract:The implementation of services that process confidential data in a mobile environment requires an adequate level of security with the strictest possible mechanisms of information protection. The dominance of mobile devices as client applications of distributed systems has led to the development of new techniques that combine traditional methods of protection with protocols leveraging the potential of numerous interfaces available from a smartphone. For this reason, an upward trend in the use of biometrics-based methods and dynamically generated OTP secrets can be observed. Mobile devices are increasingly used in complex business processes that require strong user Authentication methods, which, according to the European Commission (Regulation), must use at least two Authentication factors belonging to different categories. Therefore, on the basis of the analysis of the solutions presented so far, a distributed protocol has been proposed. It enables user Authentication using three Authentication factors: possession, knowledge, and inherence. The described Authentication scheme refers to the possibility of carrying out the process in the mobile environment of the Android platform with guaranteed Authentication support.
Yaser Jararweh - One of the best experts on this subject based on the ideXlab platform.
-
scalable and secure big data iot system based on Multifactor Authentication and lightweight cryptography
IEEE Access, 2020Co-Authors: Saleh Atiewi, Amer Alrahayfeh, Muder Almiani, Salman Yussof, Omar Alfandi, Ahed Abugabah, Yaser JararwehAbstract:Organizations share an evolving interest in adopting a cloud computing approach for Internet of Things (IoT) applications. Integrating IoT devices and cloud computing technology is considered as an effective approach to storing and managing the enormous amount of data generated by various devices. However, big data security of these organizations presents a challenge in the IoT-cloud architecture. To overcome security issues, we propose a cloud-enabled IoT environment supported by Multifactor Authentication and lightweight cryptography encryption schemes to protect big data system. The proposed hybrid cloud environment is aimed at protecting organizations' data in a highly secure manner. The hybrid cloud environment is a combination of private and public cloud. Our IoT devices are divided into sensitive and nonsensitive devices. Sensitive devices generate sensitive data, such as healthcare data; whereas nonsensitive devices generate nonsensitive data, such as home appliance data. IoT devices send their data to the cloud via a gateway device. Herein, sensitive data are split into two parts: one part of the data is encrypted using RC6, and the other part is encrypted using the Fiestel encryption scheme. Nonsensitive data are encrypted using the Advanced Encryption Standard (AES) encryption scheme. Sensitive and nonsensitive data are respectively stored in private and public cloud to ensure high security. The use of Multifactor Authentication to access the data stored in the cloud is also proposed. During login, data users send their registered credentials to the Trusted Authority (TA). The TA provides three levels of Authentication to access the stored data: first-level Authentication - read file, second-level Authentication - download file, and third-level Authentication - download file from the hybrid cloud. We implement the proposed cloud-IoT architecture in the NS3 network simulator. We evaluated the performance of the proposed architecture using metrics such as computational time, security strength, encryption time, and decryption time.
Pam J Mayhew - One of the best experts on this subject based on the ideXlab platform.
-
usable security of Authentication process new approach and practical assessment
International Conference for Internet Technology and Secured Transactions, 2015Co-Authors: Maha M Althobaiti, Pam J MayhewAbstract:Authentication mechanisms are considered the typical method to secure financial websites. Context Authentication has become increasingly important in the arena of online banking, which involves sensitive data that belong to users who trust their banks. Multifactor Authentication is the most commonly used method of strengthening the log-in process in e-banking. Developing a usable and secure Authentication approach and method is the most challenging area for researchers in the fields of security and Human-Computer Interaction (HCI). This paper describes a work-in-progress towards a new approach for authenticating users when access online banking by giving them the opportunity to choose their preferred method to log into e-banking. In our complex experiment with 100 online banking customers, we simulate an original online banking platform based on the proposed approach; then, we evaluate the usability and security of three different methods and assess user awareness of the most visible security design flaws. The initial result shows that the new system model was able to assess the usability and security of different Multifactor Authentication methods and it is considered a first attempt towards a usable and secure Authentication approach.
-
security and usability of authenticating process of online banking user experience study
International Carnahan Conference on Security Technology, 2014Co-Authors: Maha M Althobaiti, Pam J MayhewAbstract:Bank websites are secure websites considered high risk, so security is a prime concern. Authentication is extremely important because it serves as the entry point for customers to access their personal and sensitive information. To be considered effective and desirable, a banking website should provide its users with secure and usable Authentication mechanisms. Otherwise, the Authentication process likely will become unsafe and frustrating for users. This issue in turn compromises the bank’s objective to make online transactions convenient for its users. Focusing on this dilemma, this paper sought to examine the security and usability of single and Multifactor Authentication methods, which are used by most banks to strengthen the security process. However, the security and usability of Multifactor Authentication have not been closely investigated from the user’s perspective. In a survey of 302 e-banking customers who owned at least two international bank accounts, Multifactor Authentication methods were perceived as secure and trustworthy, with a high rate of usability. Token-based Authentication was perceived as more usable than SMS-based Authentication, during which a SMS is sent via mobile means.