• DocumentCode
    707555
  • Title

    Enhancing security of one-time password using Elliptic Curve Cryptography with finger-print biometric

  • Author

    Mahto, Dindayal ; Yadav, Dilip Kumar

  • Author_Institution
    Dept. of Comput. Applic., Nat. Inst. of Technol. (NIT), Jamshedpur, India
  • fYear
    2015
  • fDate
    11-13 March 2015
  • Firstpage
    1737
  • Lastpage
    1742
  • Abstract
    Security of one-time password (OTP) is essential because nowadays most of the e-commerce transactions are performed with the help of this mechanism. OTP is used to counter replay attack / eavesdropping. Replay Attack / eavesdropping is one form of attack on computing system connected to the Internet or Intranet. For achieving 112 bits of security level, RSA algorithm needs key size of 2048 bits, while Elliptic Curve Cryptography (ECC) needs key size of 224-255 bits. Another issue with most of the existing implementation of security models is storage of secret keys. Stored keys are often protected by poorly selected user passwords that can either be guessed or obtained through brute force attacks. This is a weak link in a security model and can potentially compromise the integrity of sensitive data. Combining biometrics with cryptography is seen as a possible solution. This paper suggests an enhanced security model of OTP system using ECC with finger-print biometric. This model also suggests more security with less key length and there is no need to store any private key anywhere. It focuses to create and share secret key without transmitting any private key so that no one could access the secret key except themselves.
  • Keywords
    Internet; bank data processing; computer network security; electronic commerce; fingerprint identification; intranets; public key cryptography; ECC; Internet; OTP system; RSA algorithm; brute force attacks; computing system; e-commerce transactions; eavesdropping; elliptic curve cryptography; finger-print biometric; intranet; one-time password; online banking; replay attack; secret key storage; security enhancement; security level; Authentication; Elliptic curve cryptography; Elliptic curves; Encryption; Fingerprint recognition; Biometrics; Elliptic Curve Cryptograph; Fingerprint; One-Time Password; Online Banking;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computing for Sustainable Global Development (INDIACom), 2015 2nd International Conference on
  • Conference_Location
    New Delhi
  • Print_ISBN
    978-9-3805-4415-1
  • Type

    conf

  • Filename
    7100545