首页> 外文期刊>Jordanian Journal of Computers and Information Technology >AN EFFICIENT TWO-SERVER AUTHENTICATION AND KEY EXCHANGE PROTOCOL FOR ACCESSING SECURE CLOUD SERVICES
【24h】

AN EFFICIENT TWO-SERVER AUTHENTICATION AND KEY EXCHANGE PROTOCOL FOR ACCESSING SECURE CLOUD SERVICES

机译:用于访问安全云服务的有效的两台服务器认证和密钥交换协议

获取原文
           

摘要

To avail cloud services; namely, Software as a Service (SaaS), Platform as a Service (PaaS), Infrastructure as aService (IaaS), …etc. via insecure channel, it is necessary to establish a symmetric key between end user andremote Cloud Service Server (CSS). In such a provision, both the end parties demand proper auditing so thatresources are legitimately used and privacies are maintained. To achieve this, there is a need for a robustauthentication mechanism. Towards the solution, a number of single server authenticated key agreement protocolshave been reported recently. However, they are vulnerable to many security threats, such as identitycompromization, impersonation, man-in-the-middle, replay, byzantine, offline dictionary and privileged-insiderattacks. In addition to this, most of the existing protocols adopt the single server-based authentication strategy,which are prone to single point of vulnerability and single point of failure issues. This work proposes an efficientpassword-based two-server authentication and key exchange protocol addressing the major limitations in theexisting protocols. The formal verification of the proposed protocol using Automated Validation of InternetSecurity Protocols and Applications (AVISPA) proofs that it is provably secure. The informal security analysissubstantiates that the proposed scheme has successfully addressed the existing issues. The performance studycontemplates that the overhead of the protocol is reasonable and comparable with those of other schemes. Theproposed protocol can be considered as a robust authentication protocol for a secure access to the cloud services.
机译:利用云服务;即软件即服务(SaaS),平台即服务(PaaS),基础架构即服务(IaaS)等。通过不安全的通道,有必要在最终用户和远程云服务服务器(CSS)之间建立对称密钥。在这样的规定中,双方都要求进行适当的审核,以便合法地使用资源并保持私密性。为了实现这一点,需要鲁棒的认证机制。对于该解决方案,最近已经报道了许多单服务器认证密钥协议协议。但是,它们容易受到许多安全威胁的威胁,例如身份受损,模拟,中间人,重放,拜占庭,离线字典和特权内部攻击。除此之外,大多数现有协议都采用基于服务器的单身份验证策略,因此容易出现单点漏洞和单点故障问题。这项工作提出了一个有效的基于密码的两服务器身份验证和密钥交换协议,解决了现有协议中的主要限制。使用Internet安全协议和应用程序的自动验证(AVISPA)对提议的协议进行形式验证,证明它是可证明的安全性。非正式安全分析表明,所提议的方案已成功解决了现有问题。性能研究预期该协议的开销是合理的,并且可以与其他方案的开销进行比较。所提出的协议可以被认为是用于安全访问云服务的健壮的认证协议。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号