Password Pitfalls and Dynamic Biometrics: Toward a Multi-Layer User Authentication Approach for Electronic Business

Leslie Leong, Edward J. Yerzak · 2004

With the increased awareness of the dangers of cyber-terrorism and identity fraud, the security of information systems has been propelled to the forefront as organizations strive to implement greater access control. Access control for information systems is founded upon reliable user authentication, and the predominant form of authentication remains the username-password combination. There are several vulnerabilities associated with an over-reliance upon this method of authentication, stemming from weaknesses in both the user construction of passwords and single-layer authentication techniques. The growing number of Internet business transactions highlights the need for a more secure method of user authentication that is cost-effective as well as practical. A multi-layer user authentication scheme is proposed as a solution, incorporating the use of dynamic biometric data selection and a timestamp to guard against reuse of intercepted authentication bit streams.

Read the paper · More papers on PaperTik