Robust multi-factor authentication for fragile communications
Version 2 2024-06-05, 12:23Version 2 2024-06-05, 12:23
Version 1 2015-04-02, 17:16Version 1 2015-04-02, 17:16
journal contribution
posted on 2024-06-05, 12:23authored byX Huang, Y Xiang, E Bertino, J Zhou, L Xu
In large-scale systems, user authentication usually needs the assistance from a remote central authentication server via networks. The authentication service however could be slow or unavailable due to natural disasters or various cyber attacks on communication channels. This has raised serious concerns in systems which need robust authentication in emergency situations. The contribution of this paper is two-fold. In a slow connection situation, we present a secure generic multi-factor authentication protocol to speed up the whole authentication process. Compared with another generic protocol in the literature, the new proposal provides the same function with significant improvements in computation and communication. Another authentication mechanism, which we name stand-alone authentication, can authenticate users when the connection to the central server is down. We investigate several issues in stand-alone authentication and show how to add it on multi-factor authentication protocols in an efficient and generic way.
History
Journal
IEEE Transactions on Dependable and Secure Computing