Cloud Password Manager Using Privacy-Preserved Biometrics
Title | Cloud Password Manager Using Privacy-Preserved Biometrics |
Publication Type | Conference Paper |
Year of Publication | 2014 |
Authors | Bian Yang, Huiguang Chu, Guoqiang Li, Petrovic, S., Busch, C. |
Conference Name | Cloud Engineering (IC2E), 2014 IEEE International Conference on |
Date Published | March |
Keywords | authentication, authorisation, biometrics, biometrics (access control), biometrics based authentication, cloud, cloud computing, cloud password manager, cryptography, data privacy, distributed service providers, local password manager client synchronization, master password based security, nonbiometric password manager, password leakage risk, password manager, password storage, privacy, privacy enhanced biometrics, privacy preservation, privacy-preserved biometrics, security, Synchronization, token authentication, Trusted Computing, untrusted cloud service providers, Web service account, web services |
Abstract | Using one password for all web services is not secure because the leakage of the password compromises all the web services accounts, while using independent passwords for different web services is inconvenient for the identity claimant to memorize. A password manager is used to address this security-convenience dilemma by storing and retrieving multiple existing passwords using one master password. On the other hand, a password manager liberates human brain by enabling people to generate strong passwords without worry about memorizing them. While a password manager provides a convenient and secure way to managing multiple passwords, it centralizes the passwords storage and shifts the risk of passwords leakage from distributed service providers to a software or token authenticated by a single master password. Concerned about this one master password based security, biometrics could be used as a second factor for authentication by verifying the ownership of the master password. However, biometrics based authentication is more privacy concerned than a non-biometric password manager. In this paper we propose a cloud password manager scheme exploiting privacy enhanced biometrics, which achieves both security and convenience in a privacy-enhanced way. The proposed password manager scheme relies on a cloud service to synchronize all local password manager clients in an encrypted form, which is efficient to deploy the updates and secure against untrusted cloud service providers. |
DOI | 10.1109/IC2E.2014.91 |
Citation Key | 6903519 |
- password leakage risk
- web services
- Web service account
- untrusted cloud service providers
- Trusted Computing
- token authentication
- Synchronization
- security
- privacy-preserved biometrics
- privacy preservation
- privacy enhanced biometrics
- privacy
- password storage
- password manager
- authorisation
- nonbiometric password manager
- master password based security
- local password manager client synchronization
- distributed service providers
- data privacy
- Cryptography
- cloud password manager
- Cloud Computing
- cloud
- biometrics based authentication
- biometrics (access control)
- biometrics
- authentication