首页> 外文期刊>電子情報通信学会技術研究報告. 情報セキュリティ. Information Security >Proposal of a self-delegation protocol for smart cards and mobile terminals
【24h】

Proposal of a self-delegation protocol for smart cards and mobile terminals

机译:关于智能卡和移动终端的自授权协议的提案

获取原文
获取原文并翻译 | 示例
       

摘要

Mobile Services is recently extending to several communication services such as e-commerce and contents delivery services. A key technology which makes the services secure is user authentication. The user authentication is required to protect invalid use of the services. Basic schemes of the user authentication use some secret information as an authenticator, for example secret key, shared secret, and password. A verifier checks whether user has the secret information or not. Therefore, the secret information has to be stored securely. In real world, however, user may use insecure devices to make use of the services, so that secret information such as secret key may be compromised. One solution is that the mobile terminal has some personal identification mechanisms such as biometrics to activate the mobile terminal. However, this solution is inconvenient, because it requires an additional functions which is not cost effective and additional user actions when authentication, in this paper, we propose efficient self-delegation protocols and authentication protocols. A user stores the information, which relates with strict authentication, into a tamper-resistant module, and the user keeps it in his/her home securely. Tune limited authority is delegated into the mobile terminal by communicating with the tamper-resistant module on local basis. After the delegation, the user can use remote service by using the mobile terminal within the limited time. The self-delegation makes mobile services more secure to protect the primary secret information.
机译:移动服务最近正在扩展到几种通信服务,例如电子商务和内容传递服务。确保服务安全的关键技术是用户身份验证。需要用户身份验证以保护服务的无效使用。用户身份验证的基本方案使用一些秘密信息作为身份验证者,例如秘密密钥,共享秘密和密码。验证者检查用户是否具有机密信息。因此,必须安全地存储秘密信息。但是,在现实世界中,用户可能会使用不安全的设备来使用服务,因此,诸如机密密钥之类的机密信息可能会受到损害。一种解决方案是移动终端具有一些个人识别机制,例如生物特征以激活移动终端。然而,该解决方案是不方便的,因为它需要附加的功能,这些附加功能成本效益不高,并且需要进行身份验证时采取额外的用户操作,因此,本文提出了有效的自授权协议和身份验证协议。用户将与严格认证相关的信息存储到防篡改模块中,然后将其安全地保存在他/她的家里。通过在本地与防篡改模块进行通信,将调音有限权限委派给移动终端。委派后,用户可以在有限的时间内通过移动终端使用远程服务。自授权使移动服务更加安全,可以保护主要机密信息。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号