【24h】

Security parallels between people and pervasive devices

机译:人与普及设备之间的安全并行

获取原文

摘要

Unique and challenging security problems arise due to the scarcity of computational, storage, and power resources in the low-cost pervasive computing environment. Particularly relevant examples of resource-constrained systems are low-cost radio frequency identification (RFID) systems. Surprisingly, the computational abilities of low-cost pervasive devices like RFID tags are similar to another pervasive, weak computing "device": people. Neither low-cost pervasive devices nor people can efficiently perform public-key or even symmetric cryptographic operations. Neither can store long random strings nor devote too much time or energy to security protocols. Both may need to authenticate themselves over a public channel to an untrusted terminal, without any outside help or external devices. Because of these similarities, pervasive security may benefit by adapting techniques from human-computer security, or vice versa. This article treats RFID tags as a model for other low-cost pervasive devices, and describes some of their practical constraints. Several parallels between the pervasive and human-computer security settings are discussed. Finally, this article highlights one particular human-computer authentication protocol, due to Hopper and Blum, that is immediately adaptable to low-cost RFID. Borrowing techniques from Hopper and Blum, or other human-computer protocols could lead to practical pervasive security protocols.
机译:由于在低成本普及型计算环境中缺乏计算,存储和电源资源,因此出现了独特且具有挑战性的安全问题。资源受限系统的特别相关的示例是低成本射频识别(RFID)系统。令人惊讶的是,像RFID标签这样的低成本普及型设备的计算能力类似于另一种普及型,弱计算的“设备”:人。低成本的普及型设备和人们都无法有效地执行公钥甚至对称的加密操作。既不能存储长随机字符串,也不能为安全协议投入太多时间或精力。两者都可能需要通过公共渠道向不受信任的终端进行身份验证,而无需任何外部帮助或外部设备。由于存在这些相似性,因此可以通过改编人机安全性中的技术来受益于普遍的安全性,反之亦然。本文将RFID标签视为其他低成本普及型设备的模型,并描述了它们的一些实际限制。讨论了普遍安全性和人机安全性设置之间的一些相似之处。最后,本文重点介绍了由于Hopper和Blum而引起的一种特殊的人机身份验证协议,该协议可立即适用于低成本RFID。 Hopper和Blum的借用技术或其他人机协议可能会导致实用的普遍安全协议。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号