Privacy-Preserving Implicit Authentication

Abstract : In an implicit authentication system, a user profile is used as an additional factor to strengthen the authentication of mobile users. The profile consists of features that are constructed using the history of user actions on her mobile device over time. The profile is stored on a server and is used to authenticate an access request originated from the device at a later time. An access request will include a vector of recent features measurements on the device that will be matched against the stored features to accept or reject the request. The features however include private information such as user location or web sites they have visited. In this paper we propose privacy-preserving implicit authentication which achieves implicit authentication without revealing unnecessary information about the users’ usage profiles to the server. We propose an architecture, give formal security models, and propose constructions with provable security. We consider two security models, namely for cases where the device behaves semi-honestly or maliciously.
Type de document :
Communication dans un congrès
Nora Cuppens-Boulahia; Frédéric Cuppens; Sushil Jajodia; Anas Abou El Kalam; Thierry Sans. 29th IFIP International Information Security Conference (SEC), Jun 2014, Marrakech, Morocco. Springer, IFIP Advances in Information and Communication Technology, AICT-428, pp.471-484, 2014, ICT Systems Security and Privacy Protection. 〈10.1007/978-3-642-55415-5_40〉
Liste complète des métadonnées

Littérature citée [24 références]  Voir  Masquer  Télécharger

https://hal.inria.fr/hal-01370405
Contributeur : Hal Ifip <>
Soumis le : jeudi 22 septembre 2016 - 14:39:39
Dernière modification le : mercredi 14 mars 2018 - 10:46:06

Fichier

978-3-642-55415-5_40_Chapter.p...
Fichiers produits par l'(les) auteur(s)

Licence


Distributed under a Creative Commons Paternité 4.0 International License

Identifiants

Citation

Nashad Safa, Reihaneh Safavi-Naini, Siamak Shahandashti. Privacy-Preserving Implicit Authentication. Nora Cuppens-Boulahia; Frédéric Cuppens; Sushil Jajodia; Anas Abou El Kalam; Thierry Sans. 29th IFIP International Information Security Conference (SEC), Jun 2014, Marrakech, Morocco. Springer, IFIP Advances in Information and Communication Technology, AICT-428, pp.471-484, 2014, ICT Systems Security and Privacy Protection. 〈10.1007/978-3-642-55415-5_40〉. 〈hal-01370405〉

Partager

Métriques

Consultations de la notice

165

Téléchargements de fichiers

43