• DocumentCode
    48621
  • Title

    Continuous and Transparent User Identity Verification for Secure Internet Services

  • Author

    Ceccarelli, Andrea ; Montecchi, Leonardo ; Brancati, Francesco ; Lollini, Paolo ; Marguglio, Angelo ; Bondavalli, Andrea

  • Author_Institution
    Dept. of Math. & Inf., Univ. of Firenze, Florence, Italy
  • Volume
    12
  • Issue
    3
  • fYear
    2015
  • fDate
    May-June 2015
  • Firstpage
    270
  • Lastpage
    283
  • Abstract
    Session management in distributed Internet services is traditionally based on username and password, explicit logouts and mechanisms of user session expiration using classic timeouts. Emerging biometric solutions allow substituting username and password with biometric data during session establishment, but in such an approach still a single verification is deemed sufficient, and the identity of a user is considered immutable during the entire session. Additionally, the length of the session timeout may impact on the usability of the service and consequent client satisfaction. This paper explores promising alternatives offered by applying biometrics in the management of sessions. A secure protocol is defined for perpetual authentication through continuous user verification. The protocol determines adaptive timeouts based on the quality, frequency and type of biometric data transparently acquired from the user. The functional behavior of the protocol is illustrated through Matlab simulations, while model-based quantitative analysis is carried out to assess the ability of the protocol to contrast security attacks exercised by different kinds of attackers. Finally, the current prototype for PCs and Android smartphones is discussed.
  • Keywords
    Internet; biometrics (access control); security of data; Android smart phones; Matlab simulations; PC; biometric data; biometric solutions; client satisfaction; continuous user verification; distributed Internet services; functional behavior; model-based quantitative analysis; password; secure Internet services; secure protocol; session management; transparent user identity verification; user session expiration; username; Authentication; Bioinformatics; Protocols; Servers; Smart phones; Web services; Security; authentication; mobile environments; web servers;
  • fLanguage
    English
  • Journal_Title
    Dependable and Secure Computing, IEEE Transactions on
  • Publisher
    ieee
  • ISSN
    1545-5971
  • Type

    jour

  • DOI
    10.1109/TDSC.2013.2297709
  • Filename
    6702439