透過您的圖書館登入
IP:216.73.216.100
  • 學位論文

高效率與安全的遠端使用者驗證之設計與應用

The Design and Applications of Efficient and Secure Remote User Authentication

指導教授 : 黃慧鳳

摘要


近年來,由於網際網路的發達,在電子商務、行動商務環境中,遠端使用者認證是一項重要的技術,保證只有合法使用者可以存取遠端服務,並且合法使用者存取資源之安全性及運算傳輸效率,皆須並重。 在三方密鑰交換協議中,允許使用者端與伺服器共享一個人們容易記住的密碼,讓任兩個客戶端利用伺服器端協商一個交談密鑰來進行秘密通訊。本研究將提出一個基於橢圓曲線加密(Elliptic curve cryptography,ECC)的三方密鑰交換協定。此協定不僅降低了計算成本,而且比之前的學者所提出之協定更有效率。而這個方式非常適合的應用於硬體資源效能較差之環境,例如手機用戶或智慧卡。 另一方面,為了保護使用者之認證資料被有心人士追蹤及收集,近年來,有些學者提出了一種新的動態ID為基礎的認證協定,以實現使用者的匿名性。但是這些學者的方法並不能相互認證及使用者之認證資料無法真正達成匿名性。於是,我們提出一個改進的方法,修正他們的安全缺失,以達成真正的匿名,來保護使用者的資訊。 整體而言,本研究將探討一些更有效率之遠端使用者驗證技術適用於用戶端設備較差之環境。相信我們的研究,將更有助於如手機用戶或智慧卡之傳輸的安全。

並列摘要


User authentication is an important technology to guarantee that only the legal users can access resources from the remote server. In three-party password based key exchange protocol, a client is allowed to share a human-memorable password with a trusted server such that two clients can negotiate a session key to communicate with each other secretly. Based on elliptic curve cryptography (ECC), this dissertation will propose a new three-party password based authenticated key exchange scheme. The proposed method not only reduces computation cost for remote users and a trusted server but also is more efficient than previously proposed schemes. It is very suitable for hardware-limited users such as mobile units or smart cards. To protect user from tracing, recently, new efficient dynamic ID-based authentication schemes were proposed to achieve user anonymity. However, these previously proposed schemes cannot provide mutual authentication and user anonymity properties. Then, an improved method is proposed to remedy their security weakness. Overall, this research is to investigate more efficient techniques in hardware-limited users. We hope the result of proposed method will be more suitable for secure electronic communications.

參考文獻


[1] M. Abdalla and D. Pointcheval, “Simple Password-based Encrypted Key Exchange Protocols,” Topics in Cryptology-CT-RSA 2005, Spring-Verlag, pp. 191-208, 2005.
[2] A. K. Awasthi and S. Lal, “An enhanced remote user authentication scheme using smart cards,” IEEE Transactions on Consumer Electronics, Vol. 50, No. 2, pp. 583-586, 2004.
[3] S. M. Bellovin and M. Merrit, “Encrypted Key Exchange: Password-Based Protocols Secure Against Dictionary Attacks,” Proceedings of IEEE Symposium on Research in Security and Privacy, pp. 72-84, 1992.
[5] C. K. Chan, and L. M. Cheng, “Cryptanalysis of a remote user authentication scheme using smart cards,” IEEE Transactions on Consumer Electronics, Vol. 46, No. 4, pp. 992-993, 2000.
[8] H. Y. Chien and C. H. Chen, “A remote authentication scheme preserving user anonymity,” Proceedings of the 19th International Conference on Advanced Information Networking and Applications (AINA 2005), Vol. 2, pp. 245-248, 2005.

被引用紀錄


陳許峻(2008)。以電漿輔助化學氣相沉積系統製備 低溫氮化矽薄膜阻障層在塑膠基材之研究〔碩士論文,中原大學〕。華藝線上圖書館。https://doi.org/10.6840/cycu200900576
林永欽(2006)。陶瓷(瓷磚)製造過程中產出氟化物之研究〔碩士論文,元智大學〕。華藝線上圖書館。https://doi.org/10.6838/YZU.2006.00109

延伸閱讀