Design of an Online authentication protocol using both fingerprint identification and identity based cryptography

Abstract

One of the major limitations with the authentication of users via the internet is the inherent lack of security of traditional authentication techniques, passwords, PIN numbers and cookies. With the current development of the biometric fingerprint technology market, the possibility of identifying someone online has been addressed. However, recent publication in this field shows that the lack of aliveness detection mechanism in fingerprint sensors technology, may be used to mold and reproduce exact copy of a fingerprint with its detailed shape and extended characteristics (e.g. minutiae points’ location). The presented authentication system provides the solution to this problem by using ID-based cryptography. A complete online authentication system is developed presenting the registration, login and authentication phases. The security analysis of the system is also presented.