Alexander Chefranov danışmanlığındaki tezler
13 tez · Eastern Mediterranean University
Secure Recognition-Based Graphical Authentication Scheme Using Captcha and Visual Objects
Graphical password is an alternative scheme of alphanumeric password that is very tiresome process to recall the complex password. Psychological studies of human mind argue that recalling of image is easier than alphabets or digits. In this thesis, recognition based authentication built on Captcha technology is proposed. I propose method "Click-on-Captcha-Objects", which contains Captcha based visual objects (letters of any language, digits, and user-defined images); it helps memorability of a strong password. Proposed method was analyzed by two different approaches. One of them is usability and another one is security. For usability, 40 users participated in test to analyze how many users remember the complex password. Accuracy of the proposed scheme (percentage of users remembering the strong password) was 97.25%, in contrast to Captcha + text and Click-Text methods having accuracy of 88.75% and 93%, respectively. On the other hand, security analysis of the proposed system has been done with different types of attacks, popular four Captcha breakers software are used for Captcha images recognition. The proposed system resists in 98.5% cases against four Captcha breakers attacks. In contrary, Click-Text method resists in 95.5% cases. In addition, auto-mouse clicked attack analyzed; the performance against the attack of the proposed method was 97.66%, and Click-Text method performance was 95.41%. The results indicate that for proposed method it is easy to remember the strong password compared to alphanumeric and Click-Text based authentication schemes. Hence, performance of the proposed method is better than alphanumeric and Click-Text method. Traditional schemes of authentication mostly lead to guessable and unreliable password, but "Click-on-Captcha-Objects" provides reasonable security and usability to authenticate a legitimate user. In order to check the time of generation of each image at server, an experiment has been performed at SAMSUNG (Core i5, RAM 4 GB, Processor 2.53 GHz) laptop and the result was approximately 40 milliseconds per "Click-on-Captcha-Objects" image. Keywords: Graphical based authentication, secure password, Captcha based authentication, Click-on-Captcha-Objects
Secure True Random Number Generator in Wireless Network
During last decade, Wireless LAN (WLAN) has been very important and developed area of technology and science. Nowadays a level of security that can exceed the security of a WLAN is provided by using security protocols. Not only the security of WLAN can increase by cryptography algorithms their own, but also will be more powerful if True Random Numbers are being used in Cryptography algorithms. Today it is hardly possible to disregard the vital role of random numbers in Cryptography consequently security of wireless Networks in case of key exchange algorithms or nonce to convince the other part is trusted. The aim of thesis is generating secure true random numbers in context of Ad hoc WLAN. To this aim, Diffusion RNGLigth technique, which is modification of Scatter RNGLigth technique that produced true random numbers using sensory reading on Wireless Sensor Network (WSN) [1], is implemented. These modifications consist of adding and changing some parts of the secure frameworks and using AES and Triple-DES instead of DES in encryption/decryption and CMAC. In addition, produced random numbers using Diffusion RNGLigth are evaluated by NIST statistical test. The results show that p-values of Diffusion RNGLigth using AES 60% have improved in comparison with Diffusion RNGLigth using Triple-DES, also p-values of Diffusion RNGLigth using Triple-DES 60% have improved in comparison with Scatter RNGLigth. Keywords: Ad hoc, Wireless Local Area Network (WLAN), Network Security, True Random Number Generator (TRNG), Multicasting, Diffusion RNGLigth
Analysis of Three (k, n) Secret Sharing Methods and Development of a (4, n) Method with Valid Participant Authentication, Error Detection, and 100% Repairing of Multiple Damages
The aim of this thesis is the analysis of three secret sharing methods and development of a new method having better features. We work on Yuan’s and Chang-Chen-Wang’s methods; the latter one is enhanced. Yuan proposed two methods which use least significant bits of each pixel that is easiest way to hide a secret black-white image into multiple grayscale cover images by ± 1 operation that is difficult to detect. They are (n, n) as allowing to restore the secret from n covers out of n covers; their (2, 3) only modification is also proposed by Yuan. Chang-Chen-Wang Secret grayscale image Sharing between several grayscale cover images with Authentication and Remedy method (SSAR) has participant authentication and damaged pixels repairing properties while Yuan’s methods have not these features. We implemented the algorithms and conducted experiments on them getting Peak Signal to Noise Ratio (PSNR) and Structural Similarity values similar to those obtained in the papers of Yuan and Chang-Chen-Wang. We show that SSAR may fail under made assumption of uniqueness of the covers’ identifiers, is not able fake participant recognizing, and has limited by five bits out of eight (62.5%) repairing ability of one corrupted pixel. Error and fake participant detection ability is supported by 4-bit hash value. The SSAR method is (3, n) as allowing to restore a secret from any three of n cover images. We correct assumptions on the uniqueness of the identifiers so that SSAR works now correctly and propose (4, n) SSAR enhancement, SSAR-E, allowing 100% exact restoration of a corrupted pixel by the use of any four out of n covers, and recognizing a fake participant with the help of cryptographic hash functions, which have 5-bit values that allows better error detection. Also by the use of special permutation having only one loop including all the secret image pixels, SSAR-E is able restoring all the secret image damaged pixels having just one correct pixel left. The performance and size of cover images for SSAR-E are the same as for SSAR. Keywords: Secret sharing, grayscale images, steganography, authentication, repairing
Modification of Double Voter Perceptible Okamoto Blind Signature Based Electronic Voting Protocol
Three electronic voting protocols aiming double perceptibility were considered in this thesis. The most promising of them is double voter perceptible blind signature based electronic voting protocol proposed by Baseri et al. However, it is found that generally, the protocol might fail due to the selection of as generator of (where is a product of and ) by the certificate authority as such generator does not exist. Furthermore, were chosen as generators of and as generators of (where p and q are two large prime publicly known) by the certificate authority; thus, the modular p equality checks performed in the protocol might fail because used in their exponents are congruent modulo q and not congruent modulo Euler’s totient function of . These failures are shown by providing numerical counter-examples. We proposed the way of fixing these problems. Firstly, we modified one of these equalities such that can be selected randomly in . Moreover, we included the public key of the certificate authority with random value selected in in the message sent to the voting server by the voter; thus, identity of the voter is verified. Secondly, we selected in of order . This way, we might have different values as exponent on both sides of the equality but shall be congruent modulus p. Thus, all equality checks become valid. Lastly, we removed from the message sent to the ballot-counting server by the voting server since these are not used in revealing the identity of a dishonest voter. The modifications made retained all security properties of the protocol including the double perceptibility feature. Keywords: Electronic voting, double perceptibility, blind Signature, RSA crypto-system.
Real Fingerprint Detection System (RFDS) Based on Image Quality Measures and Six Classifiers
Fingerprint detection in biometrics is an important field of study in our new modern world, many forensic departments around the world use fingerprints as the key to detect criminals and bring them justice. To improve the accuracy of fingerprint detection system we implemented a Real Fingerprint Detection System (RFDS) that has high performance level of detecting real and fake fingerprint images. In this thesis, we present an RFDS system based on image quality measures (IQM’s) to detect real fingerprint images and fake fingerprint images. We performed different RFDS experiments with 25, 10, 15, and 5 IQM’s; they showed sufficient quality of real and fake fingerprint images detection. We compared our RFDS using 25, 15, 10, and 5 IQM’s with RFDS that has used 25 IQMs. Based on the comparison in this thesis we can conclude that the best result from all these RFDS is the one with 25 IQMs, because it’s HTER score is the minimum one with 0.3%, and the worst RFDS is the one with the 15 IQMs which has the maximum HTER score with 14.8%. Keywords: Biometrics, Image Quality Measure, Real and Fake Fingerprint Image, Classifier.
Analysis, Design and Implementation of a Voting System Using a Novel Oblivious and Proxy Signature
Electronic Voting System (EVS) makes voting process convenient and more secure. In this thesis, we analyzed and implemented an existing EVS. We used the proxy and oblivious signature for our security. The proxy signature helps curb the aspect of impersonation in the EVS which is a part of the signature that allows A as an original signer to assign her/his signing privilege to someone else called B as a proxy signer. This is very useful since that a scheme will allow an assigned person B (proxy signer) to produce proxy signatures on behalf of the original signer A. Additionally, B (proxy signer) can check the identity of a person R (voter). If the person is eligible to vote, he is given the privilege to exercise her/his franchise, otherwise he or she is denied access from voting. This enables curbing impersonation during the electoral process. The oblivious signature in the EVS scheme is to help R‟s (the voter‟s) choice not to be known by anyone including the proxy signature. This has to do with having n messages as a signature in which R (the voter) could choose 1 -of- n messages to get his message signed while the proxy signer will not be able to find out on which message the voter R has got the signature. The oblivious and proxy signature is efficient in communication, computation and security. We studied and provided proofs for the Electronic Voting System, made design, implemented and tested the EVS. We also conducted experiments with the EVS. We carried out the experiments based on six phases of the existing EVS time in, compared the existing and the implemented systems. We conclude that the implemented system has a better computation time (in milliseconds) than that of the existing system.
Analysis and Implementation of a Method Resistant to Functional Dependency Attacks on Databases with Sensitive Records
The technology evolution has helped to develop large database management systems. Certain information due to its importance is qualified as sensitive with the help of security constraints (SC). Basic encryption method (BEM) encrypts sensitive cells in respective sensitive records. But It does not guarantee security because of possible data dependencies between attributes that may be used for functional dependency attack (FDA) with the help of evidence records having the same values of left-hand side attributes of functional dependencies defining right-hand side sensitive cells. Partial encryption method (PEM) in addition to sensitive cells encrypts also some attributes of functional dependences to resist FDA. These methods are investigated in the thesis, and some problems of PEM are revealed (double encryption, absence of ordering of FDs after finding minimal attribute cover (MAC)). Its modification, PEM-M, eliminating double encryption and ordering FDs according to MAC is proposed. Methods PEM and PEM-M are implemented using Windev 17 platform, where a user can load a database with any scheme automatically recognized, define its security constraints and functional dependencies. Then, the methods transform the database to a form resistant to FDA. Implementation was tested on a number of examples. Efficiency of the methods was studied on a benchmark Adults database used originally for testing PEM by their authors. PEM-M was tested in the same way but using Test database. Some experiments were done using 100 and 32K records of Test database in PEM and PEM-M in order to compare efficiency and accuracy to see which method performs better. It appear that in term of execution time, PEM can performs better with scores of 0.311 and 859.13 seconds for 100 and 32K records respectively comparing to 0,345 and 952.55 seconds for PEM-M. But, in term of accuracy, PEM-M performs better with 0% of risk of double encryption which is not the case for PEM. Keywords: Database management system, Security constraint, Sensitive cell, Sensitive record, Basic encryption method, Functional dependency, Functional dependency attack, Evidence record, Partial encryption method.
Implementation and Experiments on Fingerprint Based Authentication System (FBAS) Using Delaunay Triangulation and Voronoi Diagram
Abstract: The fingerprint identification system is of great importance nowadays. This thesis is study about the survey of Fingerprint Based Authentication System (FBAS). The FBAS is implemented as several steps such as pre-processing steps, minutia extraction, Delaunay triangulation and Voronoi diagram. The pre-processing steps such as Fourier Transformation, Histogram equalization, Binarization, Region of Interest (ROI), Sobel filter are also described in this thesis. The minutiae extraction are applied on 3x3 block according to the number of neighbours around the centre value. It is obtained using the irreversible template of each fingerprint input image by Delaunay triangulation and Voronoi diagram to enhance the encryption level of the system. In this thesis, we used similarity method to check the number of dissimilar characters between lookup strings and querying lookup string of fingerprint impressions. We evaluate the FBAS by measuring the Genuine Acceptance Rate (GAR), False Acceptance Rate (FAR) and False Rejection Rate (FRR). In this thesis, we evaluate the system by using the following databases: FVC2000DB1_B, FVC2002DB1_B and FVC2004DB1_B. The results are satisfactory for all the databases. Additionally, we conduct real-time application of our algorithm on several users’ fingerprints by using the optical fingerprint scanner that shows our algorithm’s accuracy which is reliable for real-time application. Keywords: Fingerprint Based Authentication System (FBAS), Delaunay Triangulation, Voronoi Diagram.
Implementation and Experiments on Face Detection System (FDS) Using Perceptual Quality Aware Features
This thesis is motivated by developing a face detection system for detecting faces in distorted images. Interaction between face detection and perceptual image quality is studied and analyzed to develop this robust face detection system. It is observed that accuracy of existing face detection systems are degraded with increase in distortion which is occurred due to many factors like low resolution of cameras, during transmission or storing. These types of distortions are AWGN, G Blur and JPEG. To overcome this problem, a new set of features named QUALHOG (which is a combination of NSS features and HOG features) is proposed for better and accurate face detection which augments Histogram of Oriented Gradients (HOG) features with perceptual quality-aware spatial Natural Scene Statistics (NSS) features. Face detection system based on QUALHOG features shows a great improvement in detecting faces as compared to face detection system based on HOG features. A large set of images are used for experimentation. To facilitate these experiments, a distorted face database (DFD) which contains face and non-face images by a variety of common distortion types and levels is used. This new dataset is available for download and further experimentation and it contains images at 10 distortion levels. Precision and Recall are calculated, Precision versus distortion level and Recall versus Distortion level curves are obtained to show the comparison between HOG and QUALHOG based face detection systems. Furthermore obtained results are compared with known results and presented as AUPR versus Distortion level curves to show the feasibility of FDS. Keywords: Face detection system, Distorted images, Perceptual Quality Aware features, Histogram of Oriented Gradients
Analysis of the LTE Security Algorithm ZUC with SAT Solver
Long Term Evolution (LTE) the 4th generation (4G) mobile broadband radio network is designed with special attention given to security. In order to secure the communication over the air radio network of LTE, three confidentiality and integrity cryptographic algorithms are approved by 3rd Generation Partnership Project (3GPP). ZUC, which is one of the algorithms is the third alternative to LTE. ZUC is designed using inherited properties from SNOW3G cryptographic algorithm with some improvements. However, it has been found that related keys, which are result of weak key state exists in its predecessor. Moreover, from the view point of Security Algorithms Group of Experts (SAGE) advancement in cryptanalysis may have effect on both ZUC and its predecessor, due to their design similarity, and SNOW3G weak key property. This thesis analyzed the latest version of ZUC; the analysis is to check the existence of weak key state in ZUC at the end of initialization of Linear Feedback Shift Register (LFSR) with key and initialization vector (IV). The analysis is done by Boolean satisfiability problem solver (SAT solver) program, emerging logical cryptographic algorithms analysis technique. For the analysis the key initialization procedure equations of the algorithm are converted to SAT instance, which is special input format for SAT solvers in Conjunctive Normal Form (CNF), and are fed to SAT Solver. The result showed that the latest version of ZUC LFSR after the initialization is not initialized with same value that indicates there is no weak key state problem in the key generation procedure of ZUC algorithm. Keywords: ZUC, weak key, Satisfiability, SAT solver, Logical cryptanalysis
Investigation of the Method of Authenticated Key Exchange
This thesis work investigates the method of authenticated key exchange, a key exchange protocol where communicating parties generate and exchange secret session keys for the purpose of authentication. We focused attention on the Efficient Two-Server Password-Only Authenticated Key Exchange by Xun Yi, San Ling, and Huaxiong Wang, the most recent authenticated key exchange protocol. The protocol uses two-server scenario to offer a symmetric solution for authenticated key exchange protocol in the password-only model. Before authentication process, the client chooses a password and computes password authenticator such that the password cannot be revealed from the authenticator to anyone, except the two servers conspired and sends to the two servers through a secure channel. The protocol generates shared session keys by each communicating party such that, in the result of their computations, parties arrive at a common session key. In our investigation, we discovered a problem with the protocol that will cause its failure and render it inefficient in general scenario. The problem is that the protocol does not take into account congruency of the exponents modulo Euler’s totient function, resulting in the parties arriving at different session keys at the end of computations, which we proved and illustrated by numerical counter-example. We provided a modification to the protocol by proposing that in choosing parameters whose inverses are involved in computations, care must be taken to ensure that their multiplicative inverses modulo Euler’s totient function exist. We provided a proof for the modification and a numerical example to illustrate the correctness of this modification and confirmed that the protocol works efficiently. With the proposed modification, it is certain the protocol will function without any failure. Keywords: Authenticated key exchange protocol, two-server architecture, password-only authentication, Diffie-Hellman, ElGamal encryption scheme
Parametric Real Face Images Detection System (RFIDS) Using Multiple Classifiers
Recently biometric researches against spoofing attacks has been an important role of study, today we can examine the improvement of this biometric security technology against challenging methods such as spoofing attacks. In this thesis software-based approach is presented based on image quality assessments (IQA) to discriminate real genuine face images from impostor samples, a liveness assessment method is added to the present system to ensure friendly use, processing speed, and non-intrusive biometric system. The proposed method RFIDS uses 15 image quality features to decrease the level of complexity and make the system applicable for real-time applications. The experimental results achieved from this implemented work on an available dataset generates a high degree of positive detection compared to other existing methods and that the 15 image quality measures (parameters) are efficient in classifying real faces from printed impostor samples. There are some useful information retrieved from real images using IQA that makes the system capable enough to discriminate them from printed traits. Keywords: Image quality assessment, biometric, real and spoof face detection.
Adjusting Three Schemes of Anonymous User Identification and Key Distribution
User identification, user anonymity, mutual authentication and key distribution are desirable features for securing communication in a distributed network. Yang et al, Mangipudi-Katti and Hsu-Chuang in a new efficient user identification and key distribution scheme providing enhanced security, a secure identification and key agreement protocol with user anonymity (SIKA) and a novel user identification scheme with key distribution preserving user anonymity respectively were schemes proposed for these security features. They all have a problem related with not existence of inverses of identifiers used in them. Identifiers and signatures were selected and not all the identifiers have inverse identifiers modulus N. The inverse of identifiers selected for use will not exist in all cases as the probability of selecting of non-invertible identifiers modulus N goes to one leading to the failure of the schemes that is demonstrated in this present research. In this thesis, we propose a way to improve the problem by coming up with a two theorems. The first theorem is a procedure which will ensure selection of identifiers that will always have inverse identifiers under condition of usage of RSA – likekey settings which are kept secret (prime factorization of N =p*q). This procedure has one input N=p*q which is the public parameter received from a Smart Card producing Center, a trusted third party, where p, q>2 are unknown primes, and one output identifier which is any integer number between 2 and N-1, invertible modulo N. We also show that the output identifier will always have invertible mod N and invertible signatures mod N. The second theorem guarantees that the output identifier selected in the first theorem will also have invertible identifier modulo N and it’s encrypted value will also invertible modulo N. The proposed improvement ensures the schemes preserve their features and will be efficient with no computational complexities and increased communication cost. Keywords: Identifier, inverse, authentication, prime number, factorization