...
首页> 外文期刊>Journal of The Institute of Electronics Engineers of Korea >A Study on Efficient and Secure user Authentication System based on Smart-card
【24h】

A Study on Efficient and Secure user Authentication System based on Smart-card

机译:基于智能卡的高效安全的用户认证系统研究

获取原文
获取原文并翻译 | 示例

摘要

User authentication service is an absolutely necessary condition while securely implementing an IT service system. It allows for valid users to securely log-in the system and even to access valid resources from database. For efficiently and securely authenticating users, smart-card has been used as a popular tool because of its convenience and popularity. Furthermore the smart-card can maintain its own power for computation and storage, which makes it easier to be used in all types of authenticating environment that usually needs temporary storage and additional computation for authenticating users and server. First, in 1981, Lamport has designed an authentication service protocol based on user's smart-card. However it has been criticized in aspects of efficiency and security because it uses hash chains and the revealment of server's secret values are not considered. Over the years, many smart-card based authentication service protocol have been designed. Very recently, Xu, Zhu, Feng have suggested a provable and secure smart-card based authentication protocol. In this paper, first, we define all types of attacks in the smart-card based authentication service. According to the defined attacks, however, the protocol by Xu, Zhu, Feng is weak against an attack that an attacker with secret values of server is able to impersonate a valid user without knowing password and secret values of user. An efficient and secure countermeasure is suggested, then the security is analyzed.
机译:用户身份验证服务是安全实施IT服务系统时绝对必要的条件。它允许有效用户安全地登录系统,甚至可以从数据库访问有效资源。为了有效且安全地验证用户身份,智能卡由于其便利性和普及性而被用作流行工具。此外,智能卡可以保持自己的计算和存储能力,这使得它更易于在通常需要临时存储和额外计算以认证用户和服务器的所有类型的认证环境中使用。首先,在1981年,Lamport设计了基于用户智能卡的身份验证服务协议。但是,它在效率和安全性方面受到批评,因为它使用哈希链并且不考虑服务器秘密值的泄露。多年来,已经设计了许多基于智能卡的身份验证服务协议。最近,徐,朱,冯提出了一种可验证且安全的基于智能卡的身份验证协议。在本文中,首先,我们在基于智能卡的身份验证服务中定义了所有类型的攻击。但是,根据定义的攻击,Xu,Zhu,Feng的协议对具有服务器机密值的攻击者能够假冒有效用户而不知道用户的密码和机密值的攻击是微弱的。提出了一种有效和安全的对策,然后对安全性进行了分析。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号