In the information exchange through network, the security risks always exist, that is eavesdropping, defacing, and spoofing by the attacker. PKI (Public Key Infrastructure) will prevent such attacks. But key management is very serious problem in PKI. The public key certificate is issued and distributed by certificate authority, but we think that the updating of expired certificate etc. are very costly for users. And secret key management is more serious problem. In order to solve above problems, we propose the scheme that stores protected secret key which is made by combination of biometrics and secret key in the smartcard in IDbased cryptography system. The user can restore the secret key from protected secret key by presenting his fingerprint to smartcard that has protected secret key and helper data. In our scheme, the template is not need for authentication. So, the problem of the template leakage won't arise. Lastly, we proposed the concrete operation scheme in which our scheme is used and how to make signature or authentication by applying our scheme. We show that the cost of the public key and secret key management will be reduced by using this operation scheme.
목차
Abstract 1. Introduction 2. Verification of public key validity 2.1. Public key management using ID-based cryptography 3. Biometrics 3.1. Fingerprint authentication token system 3.2. Anonymous biometrics 4. Registration of protected secret key and extraction of secret key usinganonymous biometrics 4.1. Prerequisite 4.2. Protected secret key registration 4.3. Secret key extraction 4.4. Security discussion 4.5. Comparison between fingerprint authentication systems with proposed method 5. Proposal of concrete operation method 6. Digital signature generation and authentication 6.1. Second-order headings 6.2. Authentication 7. Summary and future work 8. References
저자
Akitoshi Izumi [ Dept. of Computer Science and Communication Engineering, Kyushu University ]
Yoshifumi Ueshige [ Information Media Center, Nagasaki University ]
Kouichi Sakurai [ Dept. of Computer Science and Communication Engineering, Kyushu University ]
보안공학연구지원센터(IJSIA) [Science & Engineering Research Support Center, Republic of Korea(IJSIA)]
설립연도
2006
분야
공학>컴퓨터학
소개
1. 보안공학에 대한 각종 조사 및 연구
2. 보안공학에 대한 응용기술 연구 및 발표
3. 보안공학에 관한 각종 학술 발표회 및 전시회 개최
4. 보안공학 기술의 상호 협조 및 정보교환
5. 보안공학에 관한 표준화 사업 및 규격의 제정
6. 보안공학에 관한 산학연 협동의 증진
7. 국제적 학술 교류 및 기술 협력
8. 보안공학에 관한 논문지 발간
9. 기타 본 회 목적 달성에 필요한 사업
간행물
간행물명
International Journal of Security and Its Applications
간기
격월간
pISSN
1738-9976
수록기간
2008~2016
등재여부
SCOPUS
십진분류
KDC 505DDC 605
이 권호 내 다른 논문 / International Journal of Security and Its Applications Vol.1 No.1