Authors:
Carlos Costa
;
José Luís Oliveira
and
Augusto Silva
Affiliation:
Universidade de Aveiro, DET/IEETA, Portugal
Keyword(s):
E-Services Security, E-Commerce, Digital Credentials, Authentication and Identification.
Related
Ontology
Subjects/Areas/Topics:
B2B, B2C and C2C
;
B2C/B2B Considerations
;
Business and Social Applications
;
Communication and Software Technologies and Architectures
;
e-Business
;
Enterprise Information Systems
;
Intranet and Extranet Business Applications
;
Public Sector Applications of E-Commerce
;
Society, e-Business and e-Government
;
Software Agents and Internet Computing
;
Web Information Systems and Technologies
Abstract:
The increasing dependency of enterprise on IT has rise up major concerns on security technology and procedures. Access control mechanisms, which are the core of most security policies, are mostly based on PIN and, some times, in Public Key Cryptography (PKC). Despite these techniques can be already broadly disseminated, the storage and retrieval of security secrets is yet a sensitive and open issue for organization and users. One possible solution can be provided by the utilization of smart cards to store digital certificates and private keys. However, there are special organizations where even this solution does not solve the security problems. When users deal with sensible data and it is mandatory to prevent the delegation of access privileges to third persons new solutions must be provided. In this case the access to the secrets can be enforced by a three-factor scheme: the possession of the token, the knowledge of a PIN code and the fingerprint validation. This paper presents a P
rofessional Information Card system that dynamically combines biometrics with PKC technology to assure a stronger authentication that can be used indistinctly in Internet and Intranet scenarios. The system was designed to fulfill current mission-critical enterprises access control requirements, and was deployed, as a proof of concept, in a Healthcare Information System of a major Portuguese Hospital.
(More)