Back to Search Start Over

Security issues of Internet-based biometric authentication systems: risks of Man-in-the-Middle and BioPhishing on the example of BioWebAuth

Authors :
Elisardo González Agulla
Enrique Otero Muras
José Luis Alba Castro
Carmen García Mateo
Tobias Scheidat
Jana Dittmann
Christian Zeitz
Claus Vielhauer
Source :
Security, Forensics, Steganography, and Watermarking of Multimedia Contents
Publication Year :
2008
Publisher :
SPIE, 2008.

Abstract

Beside the optimization of biometric error rates the overall security system performance in respect to intentional security attacks plays an important role for biometric enabled authentication schemes. As traditionally most user authentication schemes are knowledge and/or possession based, firstly in this paper we present a methodology for a security analysis of Internet-based biometric authentication systems by enhancing known methodologies such as the CERT attack-taxonomy with a more detailed view on the OSI-Model. Secondly as proof of concept, the guidelines extracted from this methodology are strictly applied to an open source Internet-based biometric authentication system (BioWebAuth). As case studies, two exemplary attacks, based on the found security leaks, are investigated and the attack performance is presented to show that during the biometric authentication schemes beside biometric error performance tuning also security issues need to be addressed. Finally, some design recommendations are given in order to ensure a minimum security level.

Details

ISSN :
0277786X
Database :
OpenAIRE
Journal :
SPIE Proceedings
Accession number :
edsair.doi...........bdd918f160c8f6bf60646539d90e57f6
Full Text :
https://doi.org/10.1117/12.767632