Biometric authentication and authorisation infrastructures
Matthias Olden · University of Regensburg Publication Server (University of Regensburg) · 2010
Nowadays, replacing traditional authentication methods with authentication and authorization infrastructures (AAIs) comes down to trading several passwords for one master password, which allows users to access all services in a federation. Having only one password may be comfortable for the user, but it also raises the interest of potential impostors, who may try to overcome the weak security that a single password provides. A solution to this issue would be a more-factor AAI, combining the password with a biometric method of authentication that can work on the internet. The model presented in this work is based on typing behaviour biometrics, which can recognize a user by the way he/she types. This biometric method uses the keyboard as a sensor and is a pure software solution that can function in a web browser. Due to the fact that biometrics do not require any knowledge-based features (like passwords), biometric AAIs based on typing behaviour are comfortable for the user. Also, no special devices (like tokens) are necessary for the authentication. Additionally, biometric AAIs provide high protection against attacks by uniquely assigning a username to a certain person. These advantages make biometric AAIs interesting for practical use. As common AAIs were not especially designed to be used with biometrics, their architectures do not foresee specific biometric issues like the process of enrolment on different servers, template aging and synchronisation of biometric data (e.g. for the purpose of recognizing replay attacks). They also do not include methods of delivering information about the quality of biometric data upon the login process. A part of this research will concentrate itself upon the problems of biometrics in combination with AAIs, which will be studied both at the level of the typing behaviour biometric as well as at the level of AAIs. For this, different AAI architectures will be investigated in order to see whether they permit the use of biometrics as authentication technology and to research the necessary changes in their architectures in order to provide a reference model for a biometric AAI.