透過您的圖書館登入
IP:3.133.159.198
  • 期刊
  • OpenAccess

強化國軍智慧卡身分認證及機密機制之設計

The Design of Identity Authentication and Confidentiality Mechanism for Enhancing Military Smart Card Functionality

摘要


為精進身分認證及機密機制,國軍智慧卡於2012起即提供國軍入口網站身分認證及公文系統線上簽核運用。惟其認證機制未臻完整,且運用RSA演算法所支援之1024及2048位元(bits)金錀長度較長,使其在認證及加解密的計算成本及安全強度產生疑慮。有鑑於此,本研究以國軍某單位內部線上影音系統為例,提出:(1)採橢圓曲線建置快速安全的身分認證機制,符合鑑別性及不可否認性等安全需求。(2)採低運算成本之串流加密演算法,符合快速加解密目的。(3)結合會議金鑰與隨機亂數π(PI),使對稱式加密金鑰長度恆大於訊息,增加暴力破密難度,並提昇約4倍運算速度。(4)通訊階段不需線上憑證中心參與認證。

並列摘要


To improve the identity authentication and confidentiality mechanism, the military smart card has been used for identity authentication at web portals as well as submission/authorization in the online documentation system since 2012. However, its functionality is not complete, and the RSA-supported keys (1024/2048 bits) are fairly long to cause issues of increasing authentication and encryption/decryption costs as well as providing an insufficient security strength. To resolve this, this research takes the intranet AV system of a military organization as an example, and proposes the following: (1) using elliptic curves for building a rapid/secure mechanism to meet the authenticity and non-repudiation requirements, (2) adopting the computationally low-cost stream cipher to achieve rapid encryption and decryption, (3) combining session keys with the user-defined random number πto make symmetric encryption keys longer than messages for increasing brute-force decryption difficulty and enhancing the computation speed by 4 times, and (4) not requiring participation of online key generation centers during communication sessions.

延伸閱讀