• DocumentCode
    2018408
  • Title

    Enhancing security of one-time password using Elliptic Curve Cryptography with biometrics for e-commerce applications

  • Author

    Mahto, Dindayal ; Yadav, Dilip Kumar

  • Author_Institution
    Dept. of Comput. Applic., Nat. Inst. of Technol. Jamshedpur, Jamshedpur, India
  • fYear
    2015
  • fDate
    7-8 Feb. 2015
  • Firstpage
    1
  • Lastpage
    6
  • Abstract
    Security of one-time password (OTP) is essential because nowadays most of the e-commerce transactions are performed with the help of this mechanism. OTP is used to counter replay attack/eavesdropping. Replay attack or eavesdropping is one type of attacks on network-connected computing environment or isolated computing environment. For achieving 112 bits of security level, Rivest Shamir and Adleman (RSA) algorithm needs key size of 2048 bits, while Elliptic Curve Cryptography (ECC) needs key size of 224-255 bits. Another issue with most of the existing implementation of security models is storage of secret keys. Cryptographic keys are often kept in en-secured way that can either be guessed/social-engineered or obtained through brute force attacks. This becomes a weak link and leads integrity issues of sensitive data in a security model. To overcome the above problem, biometrics is combined with cryptography for developing strong security model. This paper suggests an enhanced security model of OTP system using ECC with palm-vein biometrie. This model also suggests better security with lesser key size than other prevalent public key crypto-model. The cryptographic keys are also not required to memorize or keep anywhere, these keys are generated as and when needed.
  • Keywords
    authorisation; biometrics (access control); electronic commerce; public key cryptography; ECC; OTP; cryptographic keys; e-commerce; eavesdropping; elliptic curve cryptography; isolated computing environment; network-connected computing environment; one-time password; palm-vein biometrics; replay attack; security model; Biological system modeling; Biometrics (access control); Elliptic curve cryptography; Elliptic curves; Veins; Biometrics; Elliptic Curve Cryptography (ECC); One-Time Password; Online Banking; Palm Vein;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer, Communication, Control and Information Technology (C3IT), 2015 Third International Conference on
  • Conference_Location
    Hooghly
  • Print_ISBN
    978-1-4799-4446-0
  • Type

    conf

  • DOI
    10.1109/C3IT.2015.7060172
  • Filename
    7060172