Biometric and Password Two-Factor Cross-Domain Authentication and Key Agreement Scheme Based on Blockchain
CSTR:
Author:
Affiliation:

Clc Number:

Fund Project:

  • Article
  • |
  • Figures
  • |
  • Metrics
  • |
  • Reference
  • |
  • Related
  • |
  • Cited by
  • |
  • Materials
  • |
  • Comments
    Abstract:

    In data sharing scenarios where users access data resources across domains, their identity legitimacy and secure communication need to be ensured. To this end, this paper proposed a two-factor, i.e., biometrics and passwords, cross-domain authentication and key agreement scheme based on blockchain. Fuzzy extraction technology is used to extract the key and public information of users’ biometrics for authentication participation, avoiding biometric information leakage. The blockchain ledger is used to store users’ identity information including biometric keys and biometric public information, ensuring the consistency of users’ identity information without any tampering. In cross-domain authentication, the authentication server in the authentication domain does not need to communicate with the authentication server in the user registration domain. Instead, it is completed by directly querying the blockchain ledger to obtain users' identity information. Security and performance analysis show that the proposed scheme can provide stronger security with less computational overhead.

    Reference
    Related
    Cited by
Get Citation

李广,范冰冰.基于区块链的生物特征和口令双因子跨域认证与密钥协商方案.计算机系统应用,2022,31(3):38-47

Copy
Share
Article Metrics
  • Abstract:
  • PDF:
  • HTML:
  • Cited by:
History
  • Received:May 05,2021
  • Revised:May 28,2021
  • Adopted:
  • Online: January 24,2022
  • Published:
Article QR Code
You are the firstVisitors
Copyright: Institute of Software, Chinese Academy of Sciences Beijing ICP No. 05046678-3
Address:4# South Fourth Street, Zhongguancun,Haidian, Beijing,Postal Code:100190
Phone:010-62661041 Fax: Email:csa (a) iscas.ac.cn
Technical Support:Beijing Qinyun Technology Development Co., Ltd.

Beijing Public Network Security No. 11040202500063