首页> 外文期刊>International journal of pervasive computing and communications >A password-authenticated secure channel for App to Java Card applet communication
【24h】

A password-authenticated secure channel for App to Java Card applet communication

机译:用于App到Java Card applet通信的经过密码验证的安全通道

获取原文
获取原文并翻译 | 示例
获取外文期刊封面目录资料

摘要

Purpose - The purpose of this paper is to design, implement and evaluate the usage of the password-authenticated secure channel protocol SRP to protect the communication of a mobile application to a Java Card applet. The usage of security and privacy sensitive systems on mobile devices, such as mobile banking, mobile credit cards, mobile ticketing or mobile digital identities has continuously risen in recent years. This development makes the protection of personal and security sensitive data on mobile devices more important than ever. Design/methodology/approach - A common approach for the protection of sensitive data is to use additional hardware such as smart cards or secure elements. The communication between such dedicated hardware and back-end management systems uses strong cryptography. However, the data transfer between applications on the mobile device and so-called applets on the dedicated hardware is often either unencrypted (and interceptable by malicious software) or encrypted with static keys stored in applications. Findings-To address this issue, this paper presents a solution for fine-grained secure application-to-applet communication based on Secure Remote Password (SRP-6a and SRP-5), an authenticated key agreement protocol, with a user-provided password at run-time. Originality/value - By exploiting the Java Card cryptographic application programming interfaces (APIs) and minor adaptations to the protocol, which do not affect the security, the authors were able to implement this scheme on Java Cards with reasonable computation time.
机译:目的-本文的目的是设计,实现和评估经过密码验证的安全通道协议SRP的使用,以保护移动应用程序与Java Card applet的通信。近年来,移动设备(例如,移动银行,移动信用卡,移动票务或移动数字身份)上对安全和隐私敏感的系统的使用不断增长。这一发展使保护移动设备上的个人和安全敏感数据比以往任何时候都更加重要。设计/方法/方法-保护敏感数据的常用方法是使用其他硬件,例如智能卡或安全元件。这种专用硬件与后端管理系统之间的通信使用了强大的加密技术。但是,移动设备上的应用程序与专用硬件上的所谓的applet之间的数据传输通常是未加密的(可被恶意软件截获)或使用存储在应用程序中的静态密钥加密。发现-为了解决这个问题,本文提出了一种基于安全远程密码(SRP-6a和SRP-5),经过身份验证的密钥协商协议以及用户提供的密码的细粒度安全应用程序到小程序通信的解决方案。在运行时。原创性/价值-通过利用不影响安全性的Java Card密码应用程序编程接口(API)和对协议的较小改动,作者能够在Java卡上以合理的计算时间实现此方案。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号