Session management in distributed Internet services is traditionally based on username and password, and explicit logouts and timeouts that expire due to idle activity of the user. Emerging biometric solutions allow substituting username and password with biometric data, but still a single verification is deemed sufficient, and the identity of a user is considered immutable during the entire session. Additionally, the length of the timeout may impact on the usability of the service and consequent client satisfaction. This paper explores promising alternatives offered by biometrics for the management of sessions. A secure protocol is defined for perpetual authentication through continuous user verification. The protocol determines adaptive timeouts selected on the basis of the quality, frequency and type of biometric data acquired transparently from the user. Protocol behavior is shown through simulations.
Improving Security of Internet Services through Continuous and Transparent User Identity Verification / Andrea Ceccarelli; Andrea Bondavalli; Francesco Brancati; Ernesto La Mattina. - STAMPA. - (2012), pp. 201-206. (Intervento presentato al convegno 31st International Symposium on Reliable Distributed Systems tenutosi a Irvine, CA, USA nel 2012-Oct) [10.1109/SRDS.2012.38].
Improving Security of Internet Services through Continuous and Transparent User Identity Verification
CECCARELLI, ANDREA;BONDAVALLI, ANDREA;BRANCATI, FRANCESCO;
2012
Abstract
Session management in distributed Internet services is traditionally based on username and password, and explicit logouts and timeouts that expire due to idle activity of the user. Emerging biometric solutions allow substituting username and password with biometric data, but still a single verification is deemed sufficient, and the identity of a user is considered immutable during the entire session. Additionally, the length of the timeout may impact on the usability of the service and consequent client satisfaction. This paper explores promising alternatives offered by biometrics for the management of sessions. A secure protocol is defined for perpetual authentication through continuous user verification. The protocol determines adaptive timeouts selected on the basis of the quality, frequency and type of biometric data acquired transparently from the user. Protocol behavior is shown through simulations.File | Dimensione | Formato | |
---|---|---|---|
06424854.pdf
Accesso chiuso
Tipologia:
Pdf editoriale (Version of record)
Licenza:
Tutti i diritti riservati
Dimensione
280.34 kB
Formato
Adobe PDF
|
280.34 kB | Adobe PDF | Richiedi una copia |
I documenti in FLORE sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.