Tunde Oduguwa
Passwordless authentication using a combination of cryptography, steganography, and biometrics
Oduguwa, Tunde; Arabo, Abdullahi
Authors
Abdullahi Arabo Abdullahi.Arabo@uwe.ac.uk
Associate professor of Cyber Science and Network Security
Abstract
User-generated passwords often pose a security risk in authentication systems. However, providing a comparative substitute poses a challenge, given the common tradeoff between security and user experience. This paper integrates cryptographic methods (both asymmetric and symmetric), steganography, and a combination of physiological and behavioural biometrics to construct a prototype for a passwordless authentication system. We demonstrate the feasibility of scalable passwordless authentication while maintaining a balance between usability and security. We employ threat modeling techniques to pinpoint the security prerequisites for the system, along with choosing appropriate cryptographic protocols. In addition, a comparative analysis is conducted, examining the security impacts of the proposed system in contrast to that of traditional password-based systems. The results from the prototype indicate that authentication is possible within a timeframe similar to passwords (within 2 s), without imposing additional hardware costs on users to enhance security or compromising usability. Given the scalable nature of the system design and the elimination of shared secrets, the financial and efficiency burdens associated with password resets are alleviated. Furthermore, the risk of breaches is mitigated as there is no longer a need to store passwords and/or their hashes. Differing from prior research, our study presents a pragmatic design and prototype that deserves consideration as a viable alternative for both password-based and passwordless authentication systems.
Journal Article Type | Article |
---|---|
Acceptance Date | Apr 22, 2024 |
Online Publication Date | May 1, 2024 |
Publication Date | Jun 1, 2024 |
Deposit Date | Jun 21, 2024 |
Publicly Available Date | Jun 25, 2024 |
Journal | Journal of Cybersecurity and Privacy |
Electronic ISSN | 2624-800X |
Publisher | MDPI |
Peer Reviewed | Peer Reviewed |
Volume | 4 |
Issue | 2 |
Pages | 278-297 |
DOI | https://doi.org/10.3390/jcp4020014 |
Public URL | https://uwe-repository.worktribe.com/output/12000571 |
Files
asswordless authentication using a combination of cryptography, steganography, and biometrics
(2.9 Mb)
PDF
Licence
http://creativecommons.org/licenses/by/4.0/
Publisher Licence URL
http://creativecommons.org/licenses/by/4.0/
You might also like
Cyber Security Challenges within the Connected Home Ecosystem Futures
(2015)
Presentation / Conference Contribution
Cybersecurity in the IoT
(2015)
Presentation / Conference Contribution
Pedagogical Approach to Effective Cybersecurity Teaching
(2019)
Book Chapter
Processing device and method of operation thereof
(-0001)
Patent
Downloadable Citations
About UWE Bristol Research Repository
Administrator e-mail: repository@uwe.ac.uk
This application uses the following open-source libraries:
SheetJS Community Edition
Apache License Version 2.0 (http://www.apache.org/licenses/)
PDF.js
Apache License Version 2.0 (http://www.apache.org/licenses/)
Font Awesome
SIL OFL 1.1 (http://scripts.sil.org/OFL)
MIT License (http://opensource.org/licenses/mit-license.html)
CC BY 3.0 ( http://creativecommons.org/licenses/by/3.0/)
Powered by Worktribe © 2025
Advanced Search