Exploring new authentication protocols for sensitive data protection on smartphones

Galdi, Chiara; Nappi, Michele; Dugelay, Jean-Luc; Yu, Yong

IEEE Communications Magazine, Vol.56, N°1, January 2018

Smartphones are increasingly becoming a tool for ubiquitous access to a number of services including but not limited to e-commerce and home banking, and are more and more used for sensitive data storage. If on the one hand this makes the smartphone a powerful tool in our private and professional life, on the other it has brought about a series of new challenging security and privacy threats and raised the need to protect users and their data through new secure authentication protocols. In this article, we illustrate how the security level of a human authentication system increases from traditional systems based on the use of passwords or badges to modern systems based on biometrics. We have moved a step forward by conceiving an authentication protocol based on the combined recognition of human face and smartphone fingerprint. Thanks to image processing techniques, both the distinctive characteristics of the face and of the device that captured the face image can be extracted from a single photo or video frame and used for a double check of user identity. The fast-technological development of smartphones, allows performing sophisticated operations on the device itself. In the edge computing perspective, the burden of biometric recognition and source camera identification can be moved on the end user side.

