International Conference on Communication, Computing and Information Technology |
Foundation of Computer Science USA |
ICCCMIT - Number 3 |
February 2013 |
Authors: V. Nirmalrani, P. Sakthivel |
40f6a8a8-ffd8-4c81-a196-c0970feb303d |
V. Nirmalrani, P. Sakthivel . Implementation Strategies for Multifactor Authentication for E-Governance Applications through Restful Webservices. International Conference on Communication, Computing and Information Technology. ICCCMIT, 3 (February 2013), 41-49.
Governance means the exercise of political, economic and administrative authority in the management of a countryâs affairs, including citizenâs interests and exercise of their legal rights and obligations. E-governance may be understood as the performance of this governance through the electronic medium in order to facilitate an efficient, speedy and transparent process of disseminating the required information to the public, and other agencies to perform the government administration activities. Authentication is the key to secure e-Governance applications and services. User name and password credentials are used for authenticating and authorizing, which is not sufficient. As Internet is more vulnerable nowadays, this one factor authentication is not secure and it is vulnerable for hacking. Even, in case of RESTful Web services, the current system doesn't provide any security measures except user name and password credentials, even which are hard coded in the invoking applications. This paper proposed a novel and sufficient solution that addresses the authentication in more secure and complex way. The proposed work uses the multi-factor authentication for e-Governance Applications through RESTful web services. Multi-factor Authentication includes One Time Password (OTP), Digital Signatures, extended Token based authentication for web services. Solutions to be delivered as Web services (Component based architecture) with certain access control which serves the following two purposes. First, it secures the application and services, and latter it provides a reusable component for authentication.