透過您的圖書館登入
IP:3.138.118.250
  • 學位論文

植基於智慧卡之多重伺服器遠端使用者驗證機制

Multi-server Remote User Authentication Mechanisms Using Smart Card

指導教授 : 張真誠
若您是本文的作者,可授權文章由華藝線上圖書館中協助推廣。

摘要


隨著網際網路發明,越來越多的服務已被發展出來,使得生活更加便利。然而,這也使惡意的攻擊者有機會去採取各式各樣的攻擊。因此,制訂一套安全的方法是非常的重要的,只允許合法的用戶去使用伺服器的服務。在過去幾年裡,因為智慧卡擁有辨識及資料處裡的能力,具備低成本,所以被廣泛用於現今的應用當中。 本篇論文中,我們提出兩個有關於智慧卡之多重伺服器驗證的機制於網絡環境。在第一個研究中,我們分析了Li et al.的驗證方法有安全漏洞,因此提出一個更安全的多伺服器驗證的方法。而此改進的方法不只有效率,還可以抵抗許多的安全攻擊,更可以吊銷實施惡意行為的合法用戶。另外,在第二個研究中,我們提出了一個基於指紋的多重伺服器驗證方法。根據安全、功能、效能之分析的結果顯示,與許多已存在的研究相較,我們的機制既有效率,還具備高度安全性。特別的是,我們的方法於指紋偵測下,可以抵抗假陽性的問題。

關鍵字

多伺服器 驗證 智慧卡 假陽性

並列摘要


With the development of the Internet, more and more services have been published and make life more convenient. However, it probably has a chance for malicious attackers to mount various attacks. Hence, it is essential to propose a well-designed secure authentication scheme which allows authorized users to access services from servers. In past years, because the smart card has the ability in identifying and data processing with low cost, it is widely for using in practical applications. In this thesis, we propose two mechanisms of multi-server remote user authentication using smart card in network environments. In the first study, we find the security weaknesses of Li et al.’s scheme and propose an improvement dynamic identity based multi-server authentication scheme. Analyses show that our proposed scheme can prevent several attacks and support the revocation of anonymity to handle the malicious behavior of a legal user with efficiency. The second study is to propose an advanced biometrics-based authentication scheme for a multi-server environment. Through a theoretical proof focused on security, functionality, and performance aspects, we show that our proposed scheme achieve higher security and efficiency as compared to previous schemes. In particular, our scheme overcomes the false positive problem in biometrics detection.

參考文獻


5. Yang WH, Shieh SP. (1999). Password authentication schemes with smart cards. Computers and Security, 18(8), 727-733.
1. Li X, Ma J, Wang W, Xiong Y, Zhang J. (2013). A novel smart card and dynamic ID based remote user authentication scheme for multi-server environments. Mathematical and Computer Modelling, 58(1-2), 85-95.
2. Chuang MC, Chen MC. (2014). An anonymous multi-server authenticated key agreement scheme based on trust computing using smart cards and biometrics. Expert Systems with Applications, 41(4), 1411-1418.
3. Lamport L. (1981). Password authentication with insecure communication. Communications of the ACM, 24(11), 770-772.
6. Sun HM. (2000). An efficient remote use authentication scheme using smart cards. IEEE Transactions on Consumer Electronics, 46(4), 958-961.

延伸閱讀