首页> 外文会议>Information Security; Lecture Notes in Computer Science; 4176 >Using Multiple Smart Cards for Signing Messages at Malicious Terminals
【24h】

Using Multiple Smart Cards for Signing Messages at Malicious Terminals

机译:使用多个智能卡在恶意终端上签名消息

获取原文
获取原文并翻译 | 示例

摘要

Having no trusted user interface, smart cards are unable to communicate with the user directly. Communication is possible with the aid of a terminal only, which leads to several security problems. For example, if the terminal is untrusted (which is a very typical scenario), it may perform a man-in-the middle attack. Thus, a malicious terminal can make the user sign documents that she would not sign otherwise. A signature that a card computes at a malicious terminal does not prove anything about the content of the signed document. What it does prove, is that the user did insert her card into a malicious terminal and she did intend to sign - something.rnIn this paper we propose a solution where a user has multiple smart cards, and each card represents a 'signal', a certain piece of information. The user encodes her message by using a subset of her cards for signing at the untrusted terminal. The recipient decodes the message by checking which cards were used. We also make use of time stamps from a trusted time stamping authority to allow cards to be used more than once.
机译:由于没有受信任的用户界面,智能卡无法直接与用户通信。仅在终端的帮助下进行通讯是可能的,这会导致一些安全问题。例如,如果终端不受信任(这是非常典型的情况),则它可能会执行中间人攻击。因此,恶意终端可以使用户签署她否则不会签名的文档。卡在恶意终端上计算出的签名不能证明已签名文档的内容。事实证明,用户确实将其卡插入了恶意终端,并且确实打算进行签名。-在本文中,我们提出了一种解决方案,即用户拥有多个智能卡,并且每个卡都代表一个“信号”,某些信息。用户通过使用其卡的子集在不受信任的终端上签名来对消息进行编码。接收者通过检查使用了哪些卡来对消息进行解码。我们还利用受信任的时间戳记机构提供的时间戳记,以允许多次使用卡。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号