A secure scheme for user authentication and authorization using OTP in android mobile environment /

Authentication and authorization play key roles in ensuring security system over any communication network especially over GSM network. It‟s explored from the literature that existing system over GSM is not enough for ensuring efficient security in terms of authentication as well as authorization. T...

Full description

Saved in:
Bibliographic Details
Main Author: Dar, Humaira
Format: Thesis
Language:English
Published: Kuala Lumpur : Kulliyyah of Engineering, International Islamic University Malaysia, 2014
Subjects:
Online Access:http://studentrepo.iium.edu.my/handle/123456789/4815
Tags: Add Tag
No Tags, Be the first to tag this record!
LEADER 034200000a22002770004500
008 140708t2014 my a g m 000 0 eng d
040 |a UIAM  |b eng 
041 |a eng 
043 |a a-my--- 
050 0 0 |a QA76.76.A65 
100 1 |a Dar, Humaira 
245 1 2 |a A secure scheme for user authentication and authorization using OTP in android mobile environment /  |c by Humaira Dar 
260 |a Kuala Lumpur :  |b Kulliyyah of Engineering, International Islamic University Malaysia,   |c 2014 
300 |a xiii, 130 leaves, :  |b ill. ;  |c 30cm. 
502 |a Thesis (MSCIE)--International Islamic University Malaysia, 2014. 
504 |a Includes bibliographical references (leaves 93-97). 
520 |a Authentication and authorization play key roles in ensuring security system over any communication network especially over GSM network. It‟s explored from the literature that existing system over GSM is not enough for ensuring efficient security in terms of authentication as well as authorization. The major security loophole found in the usage of OTP is that it generates the secure password that floats into GSM network where there is a higher degree of intrusion. Another prominent issue found in majority of the OTP usages is that it is not preferred for mobile phones due to time-synchronization that are usually based on an internal clock synchronization system. The proposed study attempts to minimize the operational cost by generating the OTP on User trusted handheld device. Because of this generation, the system is rendered secure because it is not accessible to GSM network. The system is designed on windows as well as on Android mobile environment using Java as programming tool to study the working prototype before the system can be actually deployed with an economic intention. Furthermore the system is analyzed for its ability to thwart some common attacks and a comparative performance analysis is done to establish feasibility with current hardware profile and User ergonomic behavior. The dissertation also exhibits a review of approaches and techniques that have been introduced in the past for the process of secure online authentication and authorization. From the analysis of the system, it has been seen that OTP generator for mobile hand held device takes less than 49 milliseconds on an average for different hardware profile belonging to diverse vendors. The issue of feeding of longer length of One-Time password is also resolved by incorporating byte-to-word conversion in Java, which are human readable and User friendly. By incorporating the same, results in ergonomic efficiency. The feeding time is shown to be reduced by approximately 60% with the inclusion of byte to word conversion. 
596 |a 1 
655 7 |a Theses, IIUM local 
690 |a Dissertations, Academic  |x Department of Computer and Information Engineering  |z IIUM 
710 4 |a International Islamic University Malaysia.  |b Department of Computer and Information Engineering 
856 2 |u http://studentrepo.iium.edu.my/handle/123456789/4815 
900 |a sbh-ls 
999 |c 438793  |d 469609 
952 |0 0  |6 T QA 000076.76 A65 D213S 2014  |7 0  |8 THESES  |9 759805  |a IIUM  |b IIUM  |c MULTIMEDIA  |g 0.00  |o t QA 76.76 A65 D213S 2014  |p 11100324565  |r 2017-10-20  |t 1  |v 0.00  |y THESIS 
952 |0 0  |6 TS CDF QA 76.76 A65 D213S 2014  |7 0  |8 THESES  |9 852547  |a IIUM  |b IIUM  |c MULTIMEDIA  |g 0.00  |o ts cdf QA 76.76 A65 D213S 2014  |p 11100324566  |r 2017-10-26  |t 1  |v 0.00  |y THESISDIG