Title :
Enhancing security of one-time password using Elliptic Curve Cryptography with finger-print biometric
Author :
Mahto, Dindayal ; Yadav, Dilip Kumar
Author_Institution :
Dept. of Comput. Applic., Nat. Inst. of Technol. (NIT), Jamshedpur, India
Abstract :
Security of one-time password (OTP) is essential because nowadays most of the e-commerce transactions are performed with the help of this mechanism. OTP is used to counter replay attack / eavesdropping. Replay Attack / eavesdropping is one form of attack on computing system connected to the Internet or Intranet. For achieving 112 bits of security level, RSA algorithm needs key size of 2048 bits, while Elliptic Curve Cryptography (ECC) needs key size of 224-255 bits. Another issue with most of the existing implementation of security models is storage of secret keys. Stored keys are often protected by poorly selected user passwords that can either be guessed or obtained through brute force attacks. This is a weak link in a security model and can potentially compromise the integrity of sensitive data. Combining biometrics with cryptography is seen as a possible solution. This paper suggests an enhanced security model of OTP system using ECC with finger-print biometric. This model also suggests more security with less key length and there is no need to store any private key anywhere. It focuses to create and share secret key without transmitting any private key so that no one could access the secret key except themselves.
Keywords :
Internet; bank data processing; computer network security; electronic commerce; fingerprint identification; intranets; public key cryptography; ECC; Internet; OTP system; RSA algorithm; brute force attacks; computing system; e-commerce transactions; eavesdropping; elliptic curve cryptography; finger-print biometric; intranet; one-time password; online banking; replay attack; secret key storage; security enhancement; security level; Authentication; Elliptic curve cryptography; Elliptic curves; Encryption; Fingerprint recognition; Biometrics; Elliptic Curve Cryptograph; Fingerprint; One-Time Password; Online Banking;
Conference_Titel :
Computing for Sustainable Global Development (INDIACom), 2015 2nd International Conference on
Conference_Location :
New Delhi
Print_ISBN :
978-9-3805-4415-1