Repository logoCyprus University of Technology
Log In(current)
Ελληνικά
English
  1. Home
  2. Cyprus University of Technology (Research Output)
  3. Άρθρα/Articles
  4. Killing the Password and Preserving Privacy with Device-Centric and Attribute-based Authentication
  • Details

Killing the Password and Preserving Privacy with Device-Centric and Attribute-based Authentication

Journal
IEEE Transactions on Information Forensics and Security
Date Issued
2020
Author(s)
Papadamou, Kostantinos  
Zannettou, Savvas  
Chifor, Bogdan  
Teican, Sorin  
Gugulea, George  
Recupero, Annamaria  
Caponi, Alberto  
Claudio, Pisa  
Bianchi, Giuseppe  
Gevers, Steven  
Xenakis, Christos  
Sirivianos, Michael  
DOI
10.1109/TIFS.2019.2958763
Abstract
Current authentication methods on the Web have serious weaknesses. First,
services heavily rely on the traditional password paradigm, which diminishes
the end-users' security and usability. Second, the lack of attribute-based
authentication does not allow anonymity-preserving access to services. Third,
users have multiple online accounts that often reflect distinct identity
aspects. This makes proving combinations of identity attributes hard on the
users.
In this paper, we address these weaknesses by proposing a privacy-preserving
architecture for device-centric and attribute-based authentication based on: 1)
the seamless integration between usable/strong device-centric authentication
methods and federated login solutions; 2) the separation of the concerns for
Authorization, Authentication, Behavioral Authentication and Identification to
facilitate incremental deployability, wide adoption and compliance with NIST
assurance levels; and 3) a novel centralized component that allows end-users to
perform identity profile and consent management, to prove combinations of
fragmented identity aspects, and to perform account recovery in case of device
loss. To the best of our knowledge, this is the first effort towards fusing the
aforementioned techniques under an integrated architecture. This architecture
effectively deems the password paradigm obsolete with minimal modification on
the service provider's software stack.
Funding(s)
From Real-world Identities to Privacy-preserving and Attribute-based CREDentials for Device-centric Access Control  
Subjects

Computer Science

Cryptography and Secu...

Computer Science - Ne...

Explore by
  • Collections
  • Research Outputs
  • Researchers
  • Faculty & Departments
  • Theses
  • Patents
  • Projects
  • Journals
  • Conferences
Useful Links
  • Researcher Portfolio Guide
  • Researcher Profile
  • Create an ORCID ID
  • CUT Open Access Author Fund
  • ETDS Guide
Copyright Policies

Use Sherpa/Romeo to find publisher copyright policies

Go
Go
  • SPARC Author Addendum Engine
  • National Open Access Policy in Cyprus
Deposit your work to Ktisis
  • Self-archiving. Please sign in to Ktisis.
  • Email your work to:
    library.dspace@cut.ac.cy
  • Contact your subject librarian

Member of

OpenAIREre3dataOpenDOARCOREDART
Cyprus University of Technology
Library and
Information
Services

Copyright © 2022 - Library and Information Services Feedback - Built with DSpace-CRIS - 4Science

  • Accessibility settings
  • Privacy policy
  • End User Agreement
COAR NotifyCOAR Notify