Secure Smart Card Signing with Time-based Digital Signature

Secure Smart Card Signing with Time-based Digital Signature
复制标题

使用基于时间的数字签名进行安全智能卡签名

DOI:
--
复制
发表时间:
2018
期刊:
International Conference on Computing, Networking and Communications
影响因子:
--
通讯作者:
C. Zou
C. Zou
中科院分区:
--
文献类型:
--
作者:
Hossein Rezaeighaleh;Roy Laurens;C. Zou

文献摘要

被引文献

相似文献

人们使用个人电脑、笔记本电脑、平板电脑和智能手机对公司网站和其他在线电子应用程序中的文件进行数字签名,而在此过程中,主要的网络安全挑战之一是可信数字签名。虽然大多数系统使用基于密码的身份验证来保护电子签名,但一些更关键的系统使用USB令牌和智能卡来防止身份盗窃并实施可信的数字签名过程。尽管智能卡提供了更强的安全性,但终端本身的任何弱点都可能危及智能卡的安全性。本文对当前智能卡数字签名进行了研究,并举例说明了智能卡终端中常见的基本漏洞,包括PIN嗅探和签名前篡改消息两种可能的攻击。本文针对二次攻击问题,提出了一种基于时间的智能卡数字签名机制来防御消息篡改攻击。我们的原型实现和性能分析表明,我们提出的机制是可行的,并且提供了更强的安全性。我们的方法使用流行的时间戳协议数据包,不需要任何新的密钥分发和证书颁发。
People use their personal computers, laptops, tablets and smart phones to digitally sign documents in company’s websites and other online electronic applications, and one of the main cybersecurity challenges in this process is trusted digital signature. While the majority of systems use password-based authentication to secure electronic signature, some more critical systems use USB token and smart card to prevent identity theft and implement the trusted digital signing process. Even though smart card provides stronger security, any weakness in the terminal itself can compromise the security of smart card. In this paper, we investigate current smart card digital signature, and illustrate well-known basic vulnerabilities of smart card terminal with the real implementation of two possible attacks including PIN sniffing and message alteration just before signing. As we focus on second attack in this paper, we propose a novel mechanism using time-based digital signing by smart card to defend against message alteration attack. Our prototype implementation and performance analysis illustrate that our proposed mechanism is feasible and provides stronger security. Our method uses popular timestamping protocol packets and does not require any new key distribution and certificate issuance.