首页> 外文期刊>Computer networks >A new two-server authentication and key agreement protocol for accessing secure cloud services
【24h】

A new two-server authentication and key agreement protocol for accessing secure cloud services

机译:用于访问安全云服务的新的两服务器身份验证和密钥协商协议

获取原文
获取原文并翻译 | 示例

摘要

Emerging Cloud computing paradigm came up with the on-demand ubiquitous service sharing facility via the Internet. In this synergy, the cloud service providers provide various services, namely, Infrastructure as a Service (laaS), Platform as a Service (PaaS) and Software as a Service (SaaS) to their clients. In such a provision, both the end parties demand proper auditing so that the resources can be legitimately utilized, and meanwhile the privacy is also preserved. In order to achieve this goal, there is a need for designing an efficient and robust authentication mechanism. Though other existing authentication protocols, such as Kerberos, Open Authorization (OAuth) and OpenID are proposed in the literature, they are vulnerable to various security threats such as replay, online dictionary, offline dictionary, stolen-verifier, impersonation, denial-of-service, privileged-insider and man-in-the-middle attacks. In this paper, we aim to propose an authentication protocol which overcomes these security loopholes in the existing protocols. In the proposed protocol, a new dynamic password-based two-server authentication and key exchange mechanism is proposed with the help of both public and private key cryptography. Moreover, to achieve strong user anonymity property, a new multi-factor authentication scheme with identity preservation has been also introduced. The security analysis using both the formal security using the broadly-accepted Real-Or-Random (ROR) model and the informal security show that the proposed protocol protects several well-known attacks. In addition, the formal security verification using the widely-used Automated Validation of Internet Security Protocols and Applications (AVISPA) ensures that the scheme is resilient against replay as well as man-in-the-middle attacks. Finally, the performance study contemplates that the overheads incurred in the protocol is reasonable and comparable to that of other existing state-of-art authentication protocols. High security along with comparable overheads make the proposed protocol to be robust and practical for a secure access to the cloud services. (C) 2017 Elsevier B.V. All rights reserved.
机译:新兴的云计算范例通过互联网提出了随需应变的无处不在的服务共享功能。在这种协同作用下,云服务提供商向其客户提供各种服务,即基础架构即服务(laaS),平台即服务(PaaS)和软件即服务(SaaS)。在这种规定中,双方都要求进行适当的审核,以便可以合理地利用资源,同时还可以保护隐私。为了实现该目标,需要设计一种有效且健壮的认证机制。尽管文献中提出了其他现有的身份验证协议,例如Kerberos,开放授权(OAuth)和OpenID,但它们容易受到各种安全威胁的影响,例如重播,在线字典,离线字典,验证者被盗,模仿,拒绝身份验证,服务,特权人员和中间人攻击。在本文中,我们旨在提出一种认证协议,该协议可以克服现有协议中的这些安全漏洞。在所提出的协议中,借助公钥和私钥密码学,提出了一种新的基于动态口令的两服务器身份验证和密钥交换机制。此外,为了实现强大的用户匿名性,还引入了一种新的具有身份保存的多因素身份验证方案。使用正式安全性(使用广泛接受的实数或随机数(ROR)模型)和非正式安全性进行的安全性分析表明,所提出的协议可以保护几种众所周知的攻击。此外,使用广泛使用的Internet安全协议和应用程序自动验证(AVISPA)进行的正式安全验证可确保该方案具有抵御重放和中间人攻击的弹性。最后,性能研究预期该协议中产生的开销是合理的,并且可以与其他现有的最新认证协议的开销相比较。高安全性和可比的开销使提出的协议对于安全访问云服务而言是健壮且实用的。 (C)2017 Elsevier B.V.保留所有权利。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号