首页> 外文期刊>Wireless Personal Communications >Towards Certificate-Based Authentication for Future Mobile Communications
【24h】

Towards Certificate-Based Authentication for Future Mobile Communications

机译:迈向基于证书的未来移动通信认证

获取原文
获取原文并翻译 | 示例
获取外文期刊封面目录资料

摘要

Certificate-based authentication of parties provides a powerful means for verifying claimed identities, since communicating partners do not have to exchange secrets in advance for authentication. This is especially valuable for roaming scenarios in future mobile communications where users authenticate to obtain network access—service access may potentially be based thereon in integrated approaches—and where the number of access network providers and Internet service providers is expected to increase considerably. When dealing with certificates, one must cope with the verification of complete certificate paths for security reasons. In mobile communications, additional constraints exist under which this verification work is performed. These constraints make verification more difficult when compared to non-mobile contexts. Mobile devices may have limited capacity for computation and mobile communication links may have limited bandwidth. In this paper, we propose to apply PKI servers—such as implemented at FhG-SIT—that allow the delegation of certificate path validation in order to speed up verification. Furthermore, we propose a special structure for PKI components and specific cooperation models that force certificate paths to be short, i.e., the lenghts of certificate paths are upper-bounded to certain small values depending on the conditions of specific cases. Additionally, we deal with the problem of users who do not have Internet access during the authentication phase. We explain how we solved this problem and show a gap in existing standards.
机译:各方基于证书的身份验证提供了一种强大的方法来验证所声明的身份,因为通信伙伴不必为身份验证而预先交换秘密。这对于未来的移动通信中的漫游场景特别有价值,在未来的移动通信中,用户进行身份验证以获取网络访问权-服务访问可能以集成方法基于其进行访问-并且预期访问网络提供商和Internet服务提供商的数量将大大增加。在处理证书时,出于安全原因,必须应对完整证书路径的验证。在移动通信中,存在执行该验证工作的其他约束。与非移动环境相比,这些限制使验证更加困难。移动设备的计算能力可能有限,而移动通信链路的带宽可能有限。在本文中,我们建议应用PKI服务器(例如在FhG-SIT实施的服务器),该服务器允许委派证书路径验证,以加快验证速度。此外,我们为PKI组件和特定的合作模型提出了一种特殊的结构,这种结构会强制证书路径变短,即证书路径的长度取决于特定情况的条件上限为某些较小的值。此外,我们处理在身份验证阶段无法访问Internet的用户的问题。我们解释了如何解决此问题并显示了现有标准中的空白。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号