...
首页> 外文期刊>Operating systems review >An Efficient and Secure Authentication Protocol Using Uncertified Keys
【24h】

An Efficient and Secure Authentication Protocol Using Uncertified Keys

机译:使用未认证密钥的高效安全认证协议

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

Most authentication protocols for distributed systems achieve identification and key distributions on the belief that the use of a uncertified key, i.e. the key whose freshness and authenticity cannot be immediately verified by its receiving principal while being received, should be avoided during the midway of an authentication process. In this paper we claim that using a uncertified key prudently can give performance advantages and not necessarily reduces the security of authentication protocols, as long as the validity of the key can be verified at the end of an authentication process. A nonce-based authentication protocol using uncertified keys is proposed. Its total number of messages is shown to be the minimal of all authentication protocols with the same formalized goals of authentication. The properties which make the protocol optimal in terms of message complexity are elaborated, and a formal logical analysis to the protocol is performed. The protocol is extended to counter the session key compromise problem and to support repeated authentication, in a more secure and flexible way without losing its optimality.
机译:大多数分布式系统的身份验证协议都实现了标识和密钥分配,其信念是在认证过程中应避免使用未经认证的密钥,即,其新鲜度和真实性无法在接收时立即由其接收方验证的密钥。处理。在本文中,我们认为,只要可以在身份验证过程结束时验证密钥的有效性,则谨慎地使用未经认证的密钥可以提供性能优势,并且不一定会降低身份验证协议的安全性。提出了一种使用非认证密钥的基于随机数的认证协议。它的消息总数显示为所有具有相同正式身份验证目标的身份验证协议中的最少。详细阐述了使协议在消息复杂度方面达到最佳的属性,并对协议进行了形式上的逻辑分析。该协议被扩展为以更安全和灵活的方式应对会话密钥泄露问题并支持重复身份验证,而不会失去其最优性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号