透過您的圖書館登入
IP:3.137.187.233
  • 學位論文

針對半誠實的網路管理者的無線網路匿名認證

Anonymous WiFi Authentication against Honest-but-curious Administrators

指導教授 : 蕭旭君

摘要


如今無線熱點已經廣泛部署在世界各地,然而這可能會導致位置和軌跡隱私洩露的風險,大部分過去的研究都著重在針對竊聽者可以取得的可用來唯一識別身份的MAC地址來做防範,目前的無線網路認證機制所使用的身分認證其實也會有同樣的隱私洩露風險。因此,我們提出了一個針對半誠實的網路管理者的無線網路匿名認證機制,透過直接匿名認證的特性,我們使用直接匿名認證的簽章作為無線網路認證時的身份認證可以達成匿名性和不可聯繫性,此外,我們有做出一個可以簡易部署的實作,它是由嵌入X.509的擴充欄位在用戶端的證書,搭配FreeRadius伺服器上可客製化的證書驗證機制來完成的,我們驗證我們設計的安全性和易佈署性,並且證明我們的設計和EAP-TLS相比只會增加部分邊際延遲,而和常用的PEAP相比則近乎相同。

並列摘要


Nowadays, wireless hotspots have been widely deployed around the world, which may lead to significant location and trajectory privacy risks. While most previous work focuses on protecting MAC addresses which can be used as a unique identifier against eavesdroppers, the authentication identity of existing WiFi authentication mechanisms can also be used by administrators to track users. In our work, we propose a new authentication mechanism for WiFi which supports anonymous authentication against honest-but-curious administrators. Leveraging the properties of Direct Anonymous Attestation (DAA), our scheme can achieve anonymity and unlinkability with a DAA signature as an authentication identity while authenticated by the authentication server in the WiFi network. We further build an implementation of our scheme by using an X.509 extension embedded in the client certificate and importing a customized certificate validation check on FreeRadius server. We validate the security property and demonstrate the deployability of our solution. We show that our scheme introduced marginal overhead compared with EAP-TLS and performs similarly to the widely-deployed PEAP.

參考文獻


A C implementation of elliptic-curve-based DAA project. https://github.com/ xaptum/ecdaa.
FreeRADIUS: The world’s most popular RADIUS Server. https://freeradius.org.
How the NSA is tracking people right now. http://apps.washingtonpost.com/g/page/national/how-the-nsa-is-tracking-people-right-now/634/.
If You Have a Smart Phone, Anyone Can Now Track Your Every Move. https://www.technologyreview.com/2012/04/20/19824/ if-you-have-a-smart-phone-anyone-can-now-track-your-every-move/.
No, this isn’t a scene from Minority Report. This trash can is stalk- ing you. https://arstechnica.com/information-technology/2013/08/ no-this-isnt-a-scene-from-minority-report-this-trash-can-is-stalking-you/.

延伸閱讀