One-Time Biometric Token based Authentication
Rohan Kulkarni, Anoop Namboodiri · 2014
Widely used online commerce systems require an user to submit his sole banking credentials or credit card details for availing desired services, thus involving high risks with untrusted service providers. Often used one-time password based systems provide additional transaction security, but are still incapable of differentiating between a genuine user trying to authenticate or an adversary with stolen credentials. This brings out a strong need for biometrics based one-time password systems. In this paper we propose a one-time biometric token based authentication protocol which works within the framework of current online transaction schemes allowing an user to carry out a financial transaction with a service provider which completes with an authorization from the bank. The proposed protocol is based on key-binding biometric cryptosystems and upholds the requirements of secure authentication, template protection and revocability while providing privacy to individual's biometrics and anonymity from the service provider. We demonstrate our system's security and performance using iris biometrics to authenticate individuals.