透過您的圖書館登入
IP:18.117.182.179
  • 會議論文
  • OpenAccess

適用於多重伺服器之具生物特徵身分鑑別與金鑰協定

摘要


傳統通行碼基底之身分鑑別協定是應用個人識別名稱及通行碼鑑別合法使用者的身分,然而,如果通行碼太複雜,使用者不易記憶,但是如果通行碼太簡單將可能遭受字典攻擊。對於傳統身分鑑別協定所面臨的資訊安全問題,有許多相關學者進行相關研究。其中,三因子的身分鑑別協定即是結合智慧卡、生物特徵以及通行碼,以期提高傳統身分鑑別之安全性。本文提出適用於多重伺服器之具生物特徵身分鑑別與金鑰協定,允許使用者能使用單一通行碼,登錄不同的伺服器,且能防制惡意伺服器管理者企圖假冒使用者登錄其他伺服器之攻擊。

關鍵字

生物特徵 智慧卡 身分鑑別

並列摘要


Traditional password-based user authentication protocols authenticate the legitimacy of the user by checking his valid password and identity. However, the password is either a long meaningless string, which is difficult for user to memorize, or a short easily-memorized password, which is easily suffered from password guessing attacks. Some user authentication protocols with three factors are recently proposed to achieve higher security and better user friendliness. Legitimacy of the user is authenticated by a smart card, user's biometric characteristics, and a password. We proposed a new user authentication protocol with three factors for multi-server environments based on protocol of Fan et al. which is designed for single server. It allows the user to register and login several servers by memorizing only one password. This protocol is secure against some potential attacks and impersonation attack plotted by any malicious server manager.

延伸閱讀