透過您的圖書館登入
IP:18.119.118.99
  • 學位論文

我國數位憑證應用於身份認證之研究

The Study of Digital Certificate Applied to Authentication in Taiwan

指導教授 : 林耀欽
若您是本文的作者,可授權文章由華藝線上圖書館中協助推廣。

摘要


在開放的網路環境中,如何才能確認使用者的身份及權限,並保障各種網路應用上的安全性,包括傳輸資料的隱私性(Privacy)和完整性(Integrity),身份的驗證(Authentication)以及不可否認性(Non-repudiation)。 網路社會中到處都是不確定的身份,傳統的帳號與密碼認證,似乎隨時都有被盜用或竊取的風險,也無法有效確認使用者的身份就是其本人,愈來愈多替代性的身份認證協定與方式被提出來討論及應用。目前網路上的身份認證方式,基於安全上的考量與法律上的保障(電子簽章法),大多會結合公開金鑰基礎建設(Public Key Infrastructure,PKI)認證機制。 使用者透過憑證管理中心(Certification Authority,CA)所發放的數位憑證(Digital Certificate)取得網路身份證明,目前國內許多政府憑證管理中心均已針對所屬特性對象核發數位憑證,使用者或企業開始擁有屬於自己的網路身份證。但在應用數位憑證進行身份認證的過程中,首先要考量的是數位憑證的身份管理,網路應用系統如何結合數位憑證與系統所認知的身份帳號;其次更要考量的是數位憑證的身份認證,網路應用系統如何確認數位憑證的真實性與有效性。 本研究最主要目的在於提出一個以數位憑證為基礎之身份認證管理系統模式,此一模式除了可同時適用於企業內部員工及外部使用者之身份認證作業外,亦針對不同憑證管理中心所發放的數位憑證,提供相關作業需求上所需要的考量與做法,以解決一般企業在規劃建置身份認證機制時所遇到的上述問題。

並列摘要


In the Internet world when everything is widely opened including our identities, how to properly authenticate and authorize users’ identities, and ensure its security, especially in the Privacy/Integrity/Authentication and Non-repudiation areas? There are really a lot of different unknown identities one can find on the Internet. The traditional way of authentication with username and passwords are not really secure anymore, since it has the risk of being stolen or hacked easily. As a result it is difficult to prove the authenticity of the identities even though the user is authenticated successfully. We can find a lot of different standards on this topic are under discussion. Nowadays, most authentications used in the Internet integrate with PKI (Public Key Infrastructure) so that it has better security and protection in the legal aspect. Users could obtain their digital certificates through a CA (Certification Authority) to identify themselves in the Internet world. There are a lot of government CAs in Taiwan that have already deployed a PKI that targets in its own arena; and enterprises also deploy their own internal PKI. But in the process of deploying PKI and issuing certificates to users, enterprises need to consider the management of the certificates; how to integrate them with the authentication of existing Internet applications; more importantly the Internet applications have to ensure the certificate’s authenticity and validity. The main area of this research is to propose an authentication model based on the concept of PKI and digital certificate. This authentication model will be applicable to both internal deployed PKI in enterprises; as well as different Certification Authorities found in the society; so that it will overcome some commonly seen problems in the authenticity/validity/integration topics as described above.

參考文獻


10.賴溪松、洪肇蔚,各種憑證變體及其在公開金鑰基礎建設之應用,研考雙月刊29卷1期,2005.2
17.行政院衛生署醫療憑證管理中心,憑證實務作業基準 第1.0版,2003
3.林禎吉,公開金鑰基礎建設之研究,國立成功大學電機工程學系博士論文,2003
21.National Institute of Standards and Technology (NIST), Public Key Infrastructure Study, April 1994.
22.R. Housley, W. Ford and W. Polk, D. Solo, Internet X.509 Public Key Infrastructure Certificate and CRL Profile, RFC 2459, Jan 1999.

被引用紀錄


廖喬思(2010)。憑證機制於詐騙電話防治之應用〔碩士論文,國立臺灣大學〕。華藝線上圖書館。https://doi.org/10.6342/NTU.2010.03057

延伸閱讀