首页> 外文会议>Conference on Mobile and Secure Services >Secure authentication key sharing between mobile devices based on owner identity
【24h】

Secure authentication key sharing between mobile devices based on owner identity

机译:基于所有者身份的移动设备之间的安全身份验证密钥共享

获取原文

摘要

The public key based Web authentication can be securely implemented using modern mobile devices with a hardware-assisted trusted environment such as the Trusted Execution Environment (TEE) as a secure storage of private keys. As a private key is strictly kept secret within the TEE and never leaves the device, there is a usability issue: the user must register the key separately on each device and Web site, which is burdensome for users who start using a new device. The aim of this research is to provide a solution with enhanced usability in key management by relaxing the restriction that the keys never leave the device and allowing the private keys to be shared among the devices while still maintaining an acceptable level of security. We introduce a third party that is responsible for supervising the key-sharing between devices in an authentication system. The third party performs the identification of the owner of each device to mitigate the risk of the keys being illegally shared to another person's device. Also, we propose a secure method for copying keys from the TEE of one device to that of another through a certificate-based mutually authenticated channel. We implemented the copying method in the ARM TrustZone-based TEE and showed that our approach is feasible on a commercially available smartphone.
机译:基于公钥的Web身份验证可以使用具有硬件辅助的可信环境(例如,可信执行环境(TEE))作为安全私钥存储的现代移动设备安全地实现。由于私钥在TEE中严格保密,并且永远不会离开设备,因此存在可用性问题:用户必须在每个设备和网站上分别注册密钥,这对于开始使用新设备的用户来说是沉重的负担。这项研究的目的是通过放宽密钥永远不会离开设备的限制,并允许私钥在设备之间共享,同时仍保持可接受的安全级别,来提供一种具有增强的密钥管理可用性的解决方案。我们介绍了一个第三方,该第三方负责监督身份验证系统中设备之间的密钥共享。第三方对每个设备的所有者进行标识,以减轻密钥被非法共享给另一个人的设备的风险。此外,我们提出了一种安全的方法,用于通过基于证书的相互认证通道将密钥从一个设备的TEE复制到另一个设备的TEE。我们在基于ARM TrustZone的TEE中实现了复制方法,并表明我们的方法在市售智能手机上是可行的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号