Bio-CAPTCHA Voice-Based Authentication Technique for Better Security and Usability in Cloud Computing

Author(s):  
Omar Ahmed Hedaia ◽  
Ahmed Shawish ◽  
Essam H Houssein ◽  
Hala Zayed

Cloud computing has gained increased interest in the last few years, where an increasing number of providers are converging to such a promising platform. However, the security issues are still a big concern in the cloud, where authentication is a major one. Much research has been conducted to secure the authentication, where some of them used biometric features (fingerprint, face, and voice, etc.). In general, the biometric authentication techniques have a noticeable advantage compared to the traditional techniques because biometric features are hard to be altered or forged. Nevertheless, a new generation of attacks threatens the biometric security by using brute force approaches. This article proposes a nontraditional authentication technique that was called Bio-CAPTCHA. The proposed technique uses a random voice-based password challenge that dynamically changes every time the user tries to login, which promises to significantly decrease the possibility of unauthorized access. The conducted Experimental and theoretical analysis confirms the high-security level of the proposed technique.

With the advancements in the area of science and technology, the usage of multimedia applications have raised enormously. This raise in data has led towards different issues such as storage and confidentiality. Lot of devices and techniques has been embarked to compact the data so as to safeguard the information. Recently, cloud computing is considered to be one of the notable innovations having advantages with respect to reduction in cost, increase in throughput and flexibility in usage. However there are certain security hinges that are associated with this regard. The literature reviewed showcased several techniques coined towards the safeguard of data in cloud environment. In this article, a novel biometric authentication system is developed for the ease of computing and distributing the data without any security issues.


2019 ◽  
pp. 923-945
Author(s):  
Basma Mohammed Hassan ◽  
Khaled Mohammed Fouad ◽  
Mahmoud Fathy Hassan

Cloud computing needs a strong and efficient authentication system because the user will access his rented part through a faraway connection and it will make the authentication sensor device besides the user place for identification and verification so how to know the user who claimed himself to be the legal user. Keystroke identification system as a biometric authentication technique is strongly Candidate for the security issues in cloud computing technology. Keystroke dynamics as a security system did not need extra hardware because the authentication device will be the existing keyboard based on everyone has a unique style for writing. The other biometric methods are addressed with each advantage and disadvantage along with keystroke method. In this paper, all known studies about keystroke technique are explained and compared between them according to the classification technique, number of the participated users and each study results then introduces a survey on software and hardware of other biometric authentication techniques and after the literature review is addressed then keystroke as a biometric authentication system is suggested to access cloud computing environment because it has many advantages to being a part of the known security systems which spread in our world.


2018 ◽  
Vol 7 (4.12) ◽  
pp. 47
Author(s):  
Gaurav Deep ◽  
Paramroop Kaur ◽  
Rajni Mohana

In recent times, cloud computing has influenced every sector of life, from managing user database online on the cloud to access it on the cloud makes it more flexible to use. Cloud computing has its own security issues like privacy, integrity, confidentiality and authentication. In order to access data on the cloud Authentication majorly plays a very important role. This paper presents a secure multifactor authentication that can be used for Hospital Inventory access in Virtual Private Cloud. Virtual Private cloud is having the benefit of localization as all the data of cloud are accessible within the organization. To secure Hospital Inventory access in Virtual Private Cloud this paper proposes multifactor authentication technique using Biometric, MAC address via payload .The proposed a multifactor authentication protocol which is also validated by using a validation tool Scyther. The outcomes indicate that the proposed multifactor authentication is a robust technique. 


2015 ◽  
Vol 11 (4) ◽  
pp. 99-120 ◽  
Author(s):  
Basma Mohammed Hassan ◽  
Khaled Mohammed Fouad ◽  
Mahmoud Fathy Hassan

Cloud computing needs a strong and efficient authentication system because the user will access his rented part through a faraway connection and it will make the authentication sensor device besides the user place for identification and verification so how to know the user who claimed himself to be the legal user. Keystroke identification system as a biometric authentication technique is strongly Candidate for the security issues in cloud computing technology. Keystroke dynamics as a security system did not need extra hardware because the authentication device will be the existing keyboard based on everyone has a unique style for writing. The other biometric methods are addressed with each advantage and disadvantage along with keystroke method. In this paper, all known studies about keystroke technique are explained and compared between them according to the classification technique, number of the participated users and each study results then introduces a survey on software and hardware of other biometric authentication techniques and after the literature review is addressed then keystroke as a biometric authentication system is suggested to access cloud computing environment because it has many advantages to being a part of the known security systems which spread in our world.


2020 ◽  
Vol 13 (3) ◽  
pp. 313-318 ◽  
Author(s):  
Dhanapal Angamuthu ◽  
Nithyanandam Pandian

<P>Background: The cloud computing is the modern trend in high-performance computing. Cloud computing becomes very popular due to its characteristic of available anywhere, elasticity, ease of use, cost-effectiveness, etc. Though the cloud grants various benefits, it has associated issues and challenges to prevent the organizations to adopt the cloud. </P><P> Objective: The objective of this paper is to cover the several perspectives of Cloud Computing. This includes a basic definition of cloud, classification of the cloud based on Delivery and Deployment Model. The broad classification of the issues and challenges faced by the organization to adopt the cloud computing model are explored. Examples for the broad classification are Data Related issues in the cloud, Service availability related issues in cloud, etc. The detailed sub-classifications of each of the issues and challenges discussed. The example sub-classification of the Data Related issues in cloud shall be further classified into Data Security issues, Data Integrity issue, Data location issue, Multitenancy issues, etc. This paper also covers the typical problem of vendor lock-in issue. This article analyzed and described the various possible unique insider attacks in the cloud environment. </P><P> Results: The guideline and recommendations for the different issues and challenges are discussed. The most importantly the potential research areas in the cloud domain are explored. </P><P> Conclusion: This paper discussed the details on cloud computing, classifications and the several issues and challenges faced in adopting the cloud. The guideline and recommendations for issues and challenges are covered. The potential research areas in the cloud domain are captured. This helps the researchers, academicians and industries to focus and address the current challenges faced by the customers.</P>


2020 ◽  
pp. 1-26
Author(s):  
Qinwen Hu ◽  
Muhammad Rizwan Asghar ◽  
Nevil Brownlee

HTTPS refers to an application-specific implementation that runs HyperText Transfer Protocol (HTTP) on top of Secure Socket Layer (SSL) or Transport Layer Security (TLS). HTTPS is used to provide encrypted communication and secure identification of web servers and clients, for different purposes such as online banking and e-commerce. However, many HTTPS vulnerabilities have been disclosed in recent years. Although many studies have pointed out that these vulnerabilities can lead to serious consequences, domain administrators seem to ignore them. In this study, we evaluate the HTTPS security level of Alexa’s top 1 million domains from two perspectives. First, we explore which popular sites are still affected by those well-known security issues. Our results show that less than 0.1% of HTTPS-enabled servers in the measured domains are still vulnerable to known attacks including Rivest Cipher 4 (RC4), Compression Ratio Info-Leak Mass Exploitation (CRIME), Padding Oracle On Downgraded Legacy Encryption (POODLE), Factoring RSA Export Keys (FREAK), Logjam, and Decrypting Rivest–Shamir–Adleman (RSA) using Obsolete and Weakened eNcryption (DROWN). Second, we assess the security level of the digital certificates used by each measured HTTPS domain. Our results highlight that less than 0.52% domains use the expired certificate, 0.42% HTTPS certificates contain different hostnames, and 2.59% HTTPS domains use a self-signed certificate. The domains we investigate in our study cover 5 regions (including ARIN, RIPE NCC, APNIC, LACNIC, and AFRINIC) and 61 different categories such as online shopping websites, banking websites, educational websites, and government websites. Although our results show that the problem still exists, we find that changes have been taking place when HTTPS vulnerabilities were discovered. Through this three-year study, we found that more attention has been paid to the use and configuration of HTTPS. For example, more and more domains begin to enable the HTTPS protocol to ensure a secure communication channel between users and websites. From the first measurement, we observed that many domains are still using TLS 1.0 and 1.1, SSL 2.0, and SSL 3.0 protocols to support user clients that use outdated systems. As the previous studies revealed security risks of using these protocols, in the subsequent studies, we found that the majority of domains updated their TLS protocol on time. Our 2020 results suggest that most HTTPS domains use the TLS 1.2 protocol and show that some HTTPS domains are still vulnerable to the existing known attacks. As academics and industry professionals continue to disclose attacks against HTTPS and recommend the secure configuration of HTTPS, we found that the number of vulnerable domain is gradually decreasing every year.


Cryptography ◽  
2021 ◽  
Vol 5 (1) ◽  
pp. 4
Author(s):  
Bayan Alabdullah ◽  
Natalia Beloff ◽  
Martin White

Data security has become crucial to most enterprise and government applications due to the increasing amount of data generated, collected, and analyzed. Many algorithms have been developed to secure data storage and transmission. However, most existing solutions require multi-round functions to prevent differential and linear attacks. This results in longer execution times and greater memory consumption, which are not suitable for large datasets or delay-sensitive systems. To address these issues, this work proposes a novel algorithm that uses, on one hand, the reflection property of a balanced binary search tree data structure to minimize the overhead, and on the other hand, a dynamic offset to achieve a high security level. The performance and security of the proposed algorithm were compared to Advanced Encryption Standard and Data Encryption Standard symmetric encryption algorithms. The proposed algorithm achieved the lowest running time with comparable memory usage and satisfied the avalanche effect criterion with 50.1%. Furthermore, the randomness of the dynamic offset passed a series of National Institute of Standards and Technology (NIST) statistical tests.


Author(s):  
Ahmad Salah AlAhmad ◽  
Hasan Kahtan ◽  
Yehia Ibrahim Alzoubi ◽  
Omar Ali ◽  
Ashraf Jaradat

2018 ◽  
Vol 7 (2.21) ◽  
pp. 355
Author(s):  
P Sheela Gowr ◽  
N Kumar

Cloud computing was a hasting expertise which has innovated to a collection of new explores. A sub-ordinate device for Information services, it has an ability towards encourage development by feeding convenient environments for a choice of forms of development is different sequence. Clouds usually consider being eco-friendly, however keep it has open to the diversity of some security issues to can change together the feeder as well as users of these cloud services. In this issue are principally associated to the protection of the information flow throughout also being store in the cloud, with simple problems along with data ease of use, data right to use and data confidentiality. Data encryption and service authentication scheme has been initiated by the industries to deal with them. In this paper analyse and examine different issues on security beside with the different procedure worn by the industries to solve these effects. 


Sign in / Sign up

Export Citation Format

Share Document