An anonymous and secure biometric‐based enterprise digital rights management system for mobile environment. Issue 18 (11th May 2015)
- Record Type:
- Journal Article
- Title:
- An anonymous and secure biometric‐based enterprise digital rights management system for mobile environment. Issue 18 (11th May 2015)
- Main Title:
- An anonymous and secure biometric‐based enterprise digital rights management system for mobile environment
- Authors:
- Mishra, Dheerendra
Das, Ashok Kumar
Mukhopadhyay, Sourav - Abstract:
- Abstract: Internet‐based content distribution facilitates an efficient platform to sell the digital content to the remote users. However, the digital content can be easily copied and redistributed over the network, which causes huge loss to the right holders. On the contrary, the digital rights management (DRM) systems have been introduced in order to regulate authorized content distribution. Enterprise DRM (E‐DRM) system is an application of DRM technology, which aims to prevent illegal access of data in an enterprise. Earlier works on E‐DRM do not address anonymity, which may lead to identity theft. Recently, Chang et al . proposed an efficient E‐DRM mechanism. Their scheme provides greater efficiency and protects anonymity. Unfortunately, we identify that their scheme does not resist the insider attack and password‐guessing attack. In addition, Chang et al .'s scheme has some design flaws in the authorization phase. We then point out the requirements of E‐DRM system and present the cryptanalysis of Chang et al .'s scheme. In order to remedy the security weaknesses found in Chang et al .'s scheme, we aim to present a secure and efficient E‐DRM scheme. The proposed scheme supports the authorized content key distribution and satisfies the desirable security attributes. Additionally, our scheme offers low communication and computation overheads and user's anonymity as well. Through the rigorous formal and informal security analyses, we show that our scheme is secure againstAbstract: Internet‐based content distribution facilitates an efficient platform to sell the digital content to the remote users. However, the digital content can be easily copied and redistributed over the network, which causes huge loss to the right holders. On the contrary, the digital rights management (DRM) systems have been introduced in order to regulate authorized content distribution. Enterprise DRM (E‐DRM) system is an application of DRM technology, which aims to prevent illegal access of data in an enterprise. Earlier works on E‐DRM do not address anonymity, which may lead to identity theft. Recently, Chang et al . proposed an efficient E‐DRM mechanism. Their scheme provides greater efficiency and protects anonymity. Unfortunately, we identify that their scheme does not resist the insider attack and password‐guessing attack. In addition, Chang et al .'s scheme has some design flaws in the authorization phase. We then point out the requirements of E‐DRM system and present the cryptanalysis of Chang et al .'s scheme. In order to remedy the security weaknesses found in Chang et al .'s scheme, we aim to present a secure and efficient E‐DRM scheme. The proposed scheme supports the authorized content key distribution and satisfies the desirable security attributes. Additionally, our scheme offers low communication and computation overheads and user's anonymity as well. Through the rigorous formal and informal security analyses, we show that our scheme is secure against possible known attacks. Furthermore, the simulation results for the formal security analysis using the widely accepted Automated Validation of Internet Security Protocols and Applications tool ensure that our scheme is also secure. Copyright © 2015 John Wiley & Sons, Ltd. Abstract : We have presented a secure and efficient biometric‐based content distribution scheme for the enterprise digital rights management system suitable for mobile environment. Our scheme protects user's anonymity and satisfies the other desirable security attributes. Our scheme supports mutual authentication and key agreement where a user can correctly identify the source and establish a secure session key. Our scheme is computationally efficient when compared with other existing schemes, and the rigorous formal and informal security analyses show that our scheme is secure. … (more)
- Is Part Of:
- Security and communication networks. Volume 8:Issue 18(2015)
- Journal:
- Security and communication networks
- Issue:
- Volume 8:Issue 18(2015)
- Issue Display:
- Volume 8, Issue 18 (2015)
- Year:
- 2015
- Volume:
- 8
- Issue:
- 18
- Issue Sort Value:
- 2015-0008-0018-0000
- Page Start:
- 3383
- Page End:
- 3404
- Publication Date:
- 2015-05-11
- Subjects:
- digital rights management systems -- content distribution -- authorization -- mobile user -- anonymity -- AVISPA -- security
Computer networks -- Security measures -- Periodicals
Computer security -- Periodicals
Cryptography -- Periodicals
005.805 - Journal URLs:
- http://onlinelibrary.wiley.com/journal/10.1002/(ISSN)1939-0122 ↗
https://www.hindawi.com/journals/scn/ ↗
http://onlinelibrary.wiley.com/ ↗ - DOI:
- 10.1002/sec.1266 ↗
- Languages:
- English
- ISSNs:
- 1939-0114
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library HMNTS - ELD Digital store
- Ingest File:
- 10958.xml