Session management in distributed Internet services is traditionally based on username and password, and explicit logouts and timeouts that expire due to idle activity of the user. Emerging biometric solutions allow substituting username and password with biometric data, but still a single verification is deemed sufficient, and the identity of a user is considered immutable during the entire session. Additionally, the length of the timeout may impact on the usability of the service and consequent client satisfaction. This paper explores promising alternatives offered by biometrics for the management of sessions. A secure protocol is defined for perpetual authentication through continuous user verification. The protocol determines adaptive timeouts selected on the basis of the quality, frequency and type of biometric data acquired transparently from the user. Protocol behavior is shown through simulations.

Improving Security of Internet Services through Continuous and Transparent User Identity Verification / Andrea Ceccarelli; Andrea Bondavalli; Francesco Brancati; Ernesto La Mattina. - STAMPA. - (2012), pp. 201-206. (Intervento presentato al convegno 31st International Symposium on Reliable Distributed Systems tenutosi a Irvine, CA, USA nel 2012-Oct) [10.1109/SRDS.2012.38].

Improving Security of Internet Services through Continuous and Transparent User Identity Verification

CECCARELLI, ANDREA;BONDAVALLI, ANDREA;BRANCATI, FRANCESCO;
2012

Abstract

Session management in distributed Internet services is traditionally based on username and password, and explicit logouts and timeouts that expire due to idle activity of the user. Emerging biometric solutions allow substituting username and password with biometric data, but still a single verification is deemed sufficient, and the identity of a user is considered immutable during the entire session. Additionally, the length of the timeout may impact on the usability of the service and consequent client satisfaction. This paper explores promising alternatives offered by biometrics for the management of sessions. A secure protocol is defined for perpetual authentication through continuous user verification. The protocol determines adaptive timeouts selected on the basis of the quality, frequency and type of biometric data acquired transparently from the user. Protocol behavior is shown through simulations.
2012
Reliable Distributed Systems (SRDS), 2012 IEEE 31st Symposium on
31st International Symposium on Reliable Distributed Systems
Irvine, CA, USA
2012-Oct
Andrea Ceccarelli; Andrea Bondavalli; Francesco Brancati; Ernesto La Mattina
File in questo prodotto:
File Dimensione Formato  
06424854.pdf

Accesso chiuso

Tipologia: Pdf editoriale (Version of record)
Licenza: Tutti i diritti riservati
Dimensione 280.34 kB
Formato Adobe PDF
280.34 kB Adobe PDF   Richiedi una copia

I documenti in FLORE sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificatore per citare o creare un link a questa risorsa: https://hdl.handle.net/2158/900952
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 7
  • ???jsp.display-item.citation.isi??? 3
social impact