首页> 外文期刊>Security and Communication Networks (Online) >A secure and efficient ECC‐based user anonymity preserving single sign‐on scheme for distributed computer networks
【24h】

A secure and efficient ECC‐based user anonymity preserving single sign‐on scheme for distributed computer networks

机译:用于分布式计算机网络的安全高效的基于ECC的用户匿名保留单点登录方案

获取原文
       

摘要

A user authentication in the distributed computer networks (DCNs) plays a crucial rule to verify whether the user is a legal user and can therefore be granted access to the requested services to that user. In recent years, several RSA‐based single sign‐on mechanisms have been proposed in DCNs. However, most of them cannot preserve the user anonymity when possible attacks occur. The user devices are usually battery limited (e.g., cellular phones) and the elliptic‐curve cryptosystem is much efficient than RSA cryptosystem for the battery‐limited devices. In this paper, we aim to propose a new secure elliptic‐curve cryptosystem‐based single sign‐on mechanism for user authentication and key establishment for the secure communications in a DCNs using biometric‐based smart card. In our scheme, a user only needs to remember a private password and his or her selected unique identity to authenticate and agree on a high‐entropy cryptographic one‐time session key with a provider to communicate over untrusted public networks. Through formal and informal security analysis, we show that our scheme prevents other known possible attacks. In addition, we perform simulation on our scheme for the formal security verification using the widely‐accepted Automated Validation of Internet Security Protocols and Applications tool. The simulation results ensure that our scheme is secure against replay and man‐in‐the‐middle attacks. Furthermore, our scheme provides high security along with lower computational cost and communication cost, and as a result, our scheme is much suitable for the battery‐limited devices as compared to other related RSA‐based schemes. Copyright ? 2014 John Wiley & Sons, Ltd. We have proposed a new secure elliptic‐curve cryptosystem‐based single sign‐on mechanism for user authentication and key establishment for the secure communications in a distributed computer networks using biometric‐based smart card. Through informal and formal security analysis and verification, we have shown that our scheme is secure. Further, our scheme is efficient compared to other related existing schemes.
机译:分布式计算机网络(DCN)中的用户身份验证起着至关重要的规则,以验证该用户是否为合法用户,因此可以向该用户授予对请求的服务的访问权限。近年来,在DCN中提出了几种基于RSA的单点登录机制。但是,当可能的攻击发生时,它们中的大多数不能保留用户匿名性。用户设备通常受电池限制(例如,蜂窝电话),并且对于电池受限的设备,椭圆曲线密码系统比RSA密码系统高效得多。在本文中,我们旨在提出一种新的基于安全椭圆曲线密码系统的单点登录机制,用于使用基于生物特征的智能卡的DCN中的用户身份验证和密钥建立。在我们的方案中,用户只需要记住一个私人密码和他或她选择的唯一身份即可进行身份验证,并与提供者就高熵密码一次性会话密钥达成一致,以通过不受信任的公共网络进行通信。通过正式和非正式的安全分析,我们表明我们的方案可以防止其他已知的可能的攻击。另外,我们使用广泛接受的Internet安全协议和应用程序自动验证工具对我们的计划进行仿真,以进行正式的安全验证。仿真结果确保了我们的方案对重放和中间人攻击是安全的。此外,我们的方案可提供较高的安全性,并具有较低的计算成本和通信成本,因此,与其他相关的基于RSA的方案相比,我们的方案非常适合电池受限的设备。版权? 2014年John Wiley&Sons,Ltd.我们提出了一种新的基于安全椭圆曲线密码系统的单点登录机制,用于使用基于生物特征的智能卡的用户身份验证和密钥建立,用于分布式计算机网络中的安全通信。通过非正式和正式的安全性分析和验证,我们表明我们的方案是安全的。此外,与其他相关的现有方案相比,我们的方案是有效的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号