A federated protocol for active authentication
At a glance
- Citations
- 2
- References
- 8
- Comments
- 0
Öz
Typically, a user is identified only at the beginning of a session. If they step away from the client or the session is hijacked, their assets become vulnerable. Active authentication continuously authenticates a user during a session. It seeks to verify a user's behavioral biometrics (human-computer interactions) with those from previous sessions to determine whether the current user is an impostor/guest or the original, authenticated user. This paper reports on an active authentication protocol, the first such protocol to the authors' knowledge. Developing or enhancing protocols is DARPA's third phase for active authentication development (after addressing behavioral biometric modalities for active authentication on workstations and on mobile devices). Our active-authentication protocol works in conjunction with our enhancement of the WebID protocol. The WebID protocol uses cool URIs that dereference to profiles in FOAF. Our enhancement, WebID+Biometrics, uses enrolled biometric data stored in the WebID profile, now expressed in our enhancement of FOAF. WebID+Biometrics supports “bring your own biometrics” as your biometric data are stored in your WebID profile, in a domain that you control.
Publication details
- DOI
- 10.1109/secon.2017.7925377
- OpenAlex
- W2612207803
- Document type
- conference-paper
- Language
- EN
- Last metadata update
Comments
Oturum Açın to join the discussion.