Pretražite po imenu i prezimenu autora, mentora, urednika, prevoditelja

Napredna pretraga

Pregled bibliografske jedinice broj: 1015528

Knowledge-based authentication using decentralised verifiers


Skračić, Kristian
Knowledge-based authentication using decentralised verifiers, 2018., doktorska disertacija, Fakultet elektrotehnike i računarstva, Zagreb


CROSBI ID: 1015528 Za ispravke kontaktirajte CROSBI podršku putem web obrasca

Naslov
Knowledge-based authentication using decentralised verifiers

Autori
Skračić, Kristian

Vrsta, podvrsta i kategorija rada
Ocjenski radovi, doktorska disertacija

Fakultet
Fakultet elektrotehnike i računarstva

Mjesto
Zagreb

Datum
28.02

Godina
2018

Stranica
180

Mentor
Pale, Predrag

Ključne riječi
One-time challenge generation ; user behavior profiling ; distributed architecture ; knowledge-based authentication ; question-based authentication

Sažetak
User authentication is crucial for securing digital identities in information systems. Naturally, its importance means that user authentication methods are a major target in countless cyber-attacks. The aim of this dissertation is to propose and provide an approach to authenticating human users on servers via the Internet using knowledge-based authentication methods. The developed approach is an application-layer protocol performed over the Internet by leveraging existing transport mechanisms in web services (e.g. REST-compliant Web services). Knowledge-based authentication methods are typically based on static or slowly changing data sources, thereby making them vulnerable to eavesdropping, wiretapping, and other types of attacks. Thus, an alternative approach is needed for creating an authentication challenge that competes with other authentication factors: hardware tokens and biometrics. This study proposes a new authentication approach that exploits user behavior patterns captured in non-public data sources to create unique, one-time challenges. This study proposes: (i) a model capable of representing user behavior patterns in a wide range of user activities captured from various data sources and (ii) a method for creating unique one-time challenges based on the model. The study also tests the model and method based on multiple non-public data sources such as bank transactions, phone logs, computer usage data, and e-mail correspondence. The efficacy of the study is also demonstrated using a live user pool. Most user authentication methods rely on a single verifier stored at a central location in the information system. Such information storage presents a single point of compromise from a security perspective. This dissertation proposes a distributed authentication environment in which there is no such single point of compromise. The proposed architecture does not rely on a single verifier to authenticate users, but rather a distributed authentication architecture where several authentication servers are used for user authentication. The proposed architecture allows each server to use any authentication factor. The study provides a security analysis of the proposed architecture and protocol, showing that they are secure against the attacks chosen for the analysis.

Izvorni jezik
Engleski

Znanstvena područja
Računarstvo



POVEZANOST RADA


Ustanove:
Fakultet elektrotehnike i računarstva, Zagreb

Profili:

Avatar Url Predrag Pale (mentor)

Avatar Url Kristian Skračić (autor)


Citiraj ovu publikaciju:

Skračić, Kristian
Knowledge-based authentication using decentralised verifiers, 2018., doktorska disertacija, Fakultet elektrotehnike i računarstva, Zagreb
Skračić, K. (2018) 'Knowledge-based authentication using decentralised verifiers', doktorska disertacija, Fakultet elektrotehnike i računarstva, Zagreb.
@phdthesis{phdthesis, author = {Skra\v{c}i\'{c}, Kristian}, year = {2018}, pages = {180}, keywords = {One-time challenge generation, user behavior profiling, distributed architecture, knowledge-based authentication, question-based authentication}, title = {Knowledge-based authentication using decentralised verifiers}, keyword = {One-time challenge generation, user behavior profiling, distributed architecture, knowledge-based authentication, question-based authentication}, publisherplace = {Zagreb} }
@phdthesis{phdthesis, author = {Skra\v{c}i\'{c}, Kristian}, year = {2018}, pages = {180}, keywords = {One-time challenge generation, user behavior profiling, distributed architecture, knowledge-based authentication, question-based authentication}, title = {Knowledge-based authentication using decentralised verifiers}, keyword = {One-time challenge generation, user behavior profiling, distributed architecture, knowledge-based authentication, question-based authentication}, publisherplace = {Zagreb} }




Contrast
Increase Font
Decrease Font
Dyslexic Font