Multifactor Authenticated Key Renewal

Multifactor Authenticated Key Renewal
复制标题

DOI:
10.1007/978-3-642-32298-3_14
复制
发表时间:
2011-11
期刊:
--
影响因子:
--
通讯作者:
Shin'ichiro Matsuo;D. Moriyama;M. Yung
Shin'ichiro Matsuo;D. Moriyama;M. Yung
中科院分区:
其他
文献类型:
--
作者:
Shin'ichiro Matsuo;D. Moriyama;M. Yung

文献摘要

相似文献

建立安全通道是信息安全中最重要和最基本的信任问题之一。它不仅对服务器和用户计算机非常重要,而且对任何类型的网络设备之间的全球连接也非常重要。现有的安全通道建立技术大多基于非对称密码技术,其计算量大,存储量大,并需要复杂的支持机制,如PKI。在本文中,我们考虑设置的认证与小型设备可能由人类持有,并可能嵌入在一个半安全的环境。我们提出了一个认证的密钥更新协议,只使用对称密码。该协议考虑到了嵌入式和人类持有的网络设备的其他重要因素:它涵盖了多因素身份验证,以利用安全设备所拥有的秘密以及设备所有者的难忘密码。该协议还可以允许所存储的秘密从安全设备部分泄漏。该协议的考虑是一个很好的示范设计“可信程序”在高度受限的环境中的移动的和嵌入式小型设备,预计将在未来几年内流行。
Establishing secure channels is one of the most important and fundamental trust issues in information security. It is of high important not only for servers and users computers but also for global connectivity among any kind of network devices. Most existing technologies for establishing secure channels are based on asymmetric cryptography which requires heavy computations, large memory and complicated supporting mechanism such as PKI. In this paper, we consider the setting of authentication with small devices possibly held by humans and possibly embedded in a semi secure environment. We propose a authenticated key renewal protocol which uses only symmetric cryptography. The protocol takes into account other factors important for embedded and human held network devices: It covers multi-factor authentication to take advantage of secrets possessed by the secure device as well as the memorable password of the device owner. The protocol can, further, allow partial leakage of stored secret from a secure device. The protocol’s considerations are a good demonstration of designing “trusted procedure” in the highly constrained environment of mobile and embedded small devices which is expected to be prevalent in the coming years.