透過您的圖書館登入
IP:18.117.189.7
  • 學位論文

適用無線通訊之身分驗證協定的研究

A Research on Authentication Protocols for Wireless Communications

指導教授 : 張雅芬

摘要


近年來,無線通訊相關應用改變人類的生活,越來越多的使用者透過行動裝置來分享或是獲得所需的資源。行動裝置雖被大量應用於形形色色的應用中,但卻無法計算太過複雜的運算,且資料傳輸是透過開放且不安全的通訊媒介,故在無線通訊的環境中提供安全通訊便成為一項挑戰。 另一方面,為確保被提供服務的對象為合法使用者,身分驗證便成為不可或缺的安全需求,在本研究中,我們針對常見的兩個無線通訊主題進行討論。首先我們討論Yoon等學者針對無線通訊環境提出一個使用者身分驗證方法,其能讓使用者可驗證外籍伺服器。但經過詳細分析後,我們發現因為Yoon等學者的方法中,使用者會傳送固定參數,故無提供匿名性,且該方法無法抵禦ID-竊取攻擊,我們以Rabin所提出之密碼系統與時間戳來克服所發現之安全缺失來提出改進方案。除此之外,我們的方法亦提供金鑰協議與雙向驗證之功能。接著,我們針對目前無線通訊研究重要議題─車載網路進行研究,有鑒於車載網路相關應用被陸續提出,如何設計一個適用於車載網路且支援快速切換之身分驗證協定,便成為車載網路應用的成功關鍵。在2013年,Li及Liu學者利用動態回合機密程序提出車載網路適用且支援快速切換之身分驗證方法,並宣稱他們的方法滿足先前的特殊安全需求並使車輛與路側單元可相互驗證。隨後,Jia等學者指出他們的方法有下列三項缺失:(1)伺服器將成為瓶頸、(2)無法抵禦位置偵測、與(3)無法抵禦平行會議攻擊。因此我們提出了一個適用於車載網路且支援快速切換之身分驗證協定,該協定需確實滿足下列四項屬性: (1)位置隱私、(2)快速切換、(3)安全性、與(4)AS輕計算量。

並列摘要


In recent years, wireless communication applications change human life. More and more users tend to share or obtain required resources via mobile devices. Although mobile devices are used in various applications, they are unable to execute complex computational operations. And they transmit data through an open but insure channel. Consequently, how to ensure security for wireless communications becomes a challenge. On the other hand, authentication is essential for applications of wireless communications to ensure that only legal users can access resources. In the thesis, there are two main subjects. First, for the specific properties of wireless communications, Yoon et al. proposed a useful authentication scheme to authenticate foreign agents with fixed information and protect anonymity. However, it does not provide user anonymity actually and thus suffers from ID-theft attack. In this thesis, we propose an improvement to overcome the found weaknesses by employing the Rabin’s cryptology and timestamp. Moreover, key agreement and mutual authentication are provided in our scheme. Second, we carry on research on vehicular ad hoc networks (VANETs), which is an important topic of wireless communications. Due to that more and more applications in VANETs are proposed, how to design an identity authentication protocol supporting fast handover becomes the key to successful VANETs applications. In 2013, Li and Liu proposed an identity authentication protocol for VANETs. They claimed their protocol ensured both efficiency and security and achieved fast handover with privacy protection. Later, Jia et al. show that their protocol is vulnerable to three drawbacks, protocol bottleneck, location detection, and parallel session attack. In this thesis, we propose a fast-handover-supported authentication protocol for VANETs that ensures (1) location privacy, (2) fast handover, (3) security, and (4) the light computation load of AAA server.

參考文獻


[1] L. Lamport, “Password authentication with insecure communication,” Communications of the ACM, vol. 24, pp. 770-772, 1981.
[3] M. S. Hwang and L. H. Li, “A new remote user authentication scheme using smart cards,” IEEE Transactions on Consumer Electronics, vol. 46, pp. 28-30, 2000.
[4] C. K. Chan, “Cryptanalysis of a remote user authentication scheme using smart cards,” IEEE Transactions on Consumer Electronics, vol. 46, pp. 992-993, 2000.
[5] H. M. Sun, “An efficient remote use authentication scheme using smart cards,” IEEE Transactions on Consumer Electronics, vol. 46, pp. 958-961, 2000.
[6] S. Q. Wang, J.Y. Wang, and Y. Z. Li, “The web security password authentication based the single-block hash function,” IERI Procedia, vol. 4, pp. 2-7, 2013.

延伸閱讀