A novel authentication scheme to increase security for non-repudiation of users

Protection of sensitive information is a growing concern worldwide. Failure to protect sensitive information can lead to loss of clients in the banking sector or threaten national security. Access to sensitive information starts with e-authentication. Most authentication systems are designed for aut...

Full description

Bibliographic Details
Main Authors: Hussein, Khalid Waleed, Mohd. Sani, Nor Fazlida, Mahmod, Ramlan, Abdullah@Selimun, Mohd. Taufik
Format: Article
Language:English
Published: CMR Institute of Technology 2013
Online Access:http://psasir.upm.edu.my/id/eprint/30637/1/A%20novel%20authentication%20scheme%20to%20increase%20security%20for%20non.pdf
_version_ 1825947745918124032
author Hussein, Khalid Waleed
Mohd. Sani, Nor Fazlida
Mahmod, Ramlan
Abdullah@Selimun, Mohd. Taufik
author_facet Hussein, Khalid Waleed
Mohd. Sani, Nor Fazlida
Mahmod, Ramlan
Abdullah@Selimun, Mohd. Taufik
author_sort Hussein, Khalid Waleed
collection UPM
description Protection of sensitive information is a growing concern worldwide. Failure to protect sensitive information can lead to loss of clients in the banking sector or threaten national security. Access to sensitive information starts with e-authentication. Most authentication systems are designed for authenticated users only. However, the user is not the only party that needs to be authenticated to ensure the security of transactions on the Internet. Existing one-time password (OTP) mechanism cannot guarantee non-repudiation and fail to guarantee reuse of a stolen device, which is used in authentication.A novel authentication scheme based on OTP is presented in this paper. This paper proposes a secure multi-factor electronic authentication mechanism. This mechanism is intended to authenticate both the user and the mobile device of the user to ensure non-repudiation and protect the integrity of the OTP against adversarial attacks. The proposed mechanism can detect whether the mobile device is in the hands of the rightful owner before the OTP is sent to the user. The system requires each user to have a unique phone number and a unique mobile device (unique International Mobile Equipment Identity (IMEI)), in addition to an ID card number. The proposed system can ensure that the user who misuses the system becomes liable for the act committed. Therefore, the proposed system can be used in e-banking, e-government,and e-commerce systems, among other areas requiring high-security guarantees.
first_indexed 2024-03-06T08:18:10Z
format Article
id upm.eprints-30637
institution Universiti Putra Malaysia
language English
last_indexed 2024-03-06T08:18:10Z
publishDate 2013
publisher CMR Institute of Technology
record_format dspace
spelling upm.eprints-306372015-09-11T00:08:51Z http://psasir.upm.edu.my/id/eprint/30637/ A novel authentication scheme to increase security for non-repudiation of users Hussein, Khalid Waleed Mohd. Sani, Nor Fazlida Mahmod, Ramlan Abdullah@Selimun, Mohd. Taufik Protection of sensitive information is a growing concern worldwide. Failure to protect sensitive information can lead to loss of clients in the banking sector or threaten national security. Access to sensitive information starts with e-authentication. Most authentication systems are designed for authenticated users only. However, the user is not the only party that needs to be authenticated to ensure the security of transactions on the Internet. Existing one-time password (OTP) mechanism cannot guarantee non-repudiation and fail to guarantee reuse of a stolen device, which is used in authentication.A novel authentication scheme based on OTP is presented in this paper. This paper proposes a secure multi-factor electronic authentication mechanism. This mechanism is intended to authenticate both the user and the mobile device of the user to ensure non-repudiation and protect the integrity of the OTP against adversarial attacks. The proposed mechanism can detect whether the mobile device is in the hands of the rightful owner before the OTP is sent to the user. The system requires each user to have a unique phone number and a unique mobile device (unique International Mobile Equipment Identity (IMEI)), in addition to an ID card number. The proposed system can ensure that the user who misuses the system becomes liable for the act committed. Therefore, the proposed system can be used in e-banking, e-government,and e-commerce systems, among other areas requiring high-security guarantees. CMR Institute of Technology 2013-07 Article PeerReviewed application/pdf en http://psasir.upm.edu.my/id/eprint/30637/1/A%20novel%20authentication%20scheme%20to%20increase%20security%20for%20non.pdf Hussein, Khalid Waleed and Mohd. Sani, Nor Fazlida and Mahmod, Ramlan and Abdullah@Selimun, Mohd. Taufik (2013) A novel authentication scheme to increase security for non-repudiation of users. International Journal of Computer Science and Mobile Computing, 2 (7). pp. 396-405. ISSN 2320-088X http://ijcsmc.com/docs/papers/July2013/V2I7201395.pdf
spellingShingle Hussein, Khalid Waleed
Mohd. Sani, Nor Fazlida
Mahmod, Ramlan
Abdullah@Selimun, Mohd. Taufik
A novel authentication scheme to increase security for non-repudiation of users
title A novel authentication scheme to increase security for non-repudiation of users
title_full A novel authentication scheme to increase security for non-repudiation of users
title_fullStr A novel authentication scheme to increase security for non-repudiation of users
title_full_unstemmed A novel authentication scheme to increase security for non-repudiation of users
title_short A novel authentication scheme to increase security for non-repudiation of users
title_sort novel authentication scheme to increase security for non repudiation of users
url http://psasir.upm.edu.my/id/eprint/30637/1/A%20novel%20authentication%20scheme%20to%20increase%20security%20for%20non.pdf
work_keys_str_mv AT husseinkhalidwaleed anovelauthenticationschemetoincreasesecurityfornonrepudiationofusers
AT mohdsaninorfazlida anovelauthenticationschemetoincreasesecurityfornonrepudiationofusers
AT mahmodramlan anovelauthenticationschemetoincreasesecurityfornonrepudiationofusers
AT abdullahselimunmohdtaufik anovelauthenticationschemetoincreasesecurityfornonrepudiationofusers
AT husseinkhalidwaleed novelauthenticationschemetoincreasesecurityfornonrepudiationofusers
AT mohdsaninorfazlida novelauthenticationschemetoincreasesecurityfornonrepudiationofusers
AT mahmodramlan novelauthenticationschemetoincreasesecurityfornonrepudiationofusers
AT abdullahselimunmohdtaufik novelauthenticationschemetoincreasesecurityfornonrepudiationofusers