새로운 공개키 프레임워크와 PAN을 위한 응용
- Alternative Title
- A New Public Key Framework and its Applications to PAN
- Abstract
- Without doubt, the promise of Public Key Infrastructure (PKI) technology has attracted a significant amount of attention to support secure and authenticated services in the heterogeneous networks. The IETF PKIX Working Group is developing the Internet standards to support an X.509-based PKI, which provides a framework on services related to issuing public key certificates and distributing revocation information. The lack of a mechanism that provides efficient and timely distribution of certification revocatino information is a main issue for implementing more efficient PKI environment. The existing certificate revocation schemes place a considerable processing. commucication. and storage overheads on certificate authority(CA) as well as the relying parties.
In this thesis, the main target of our research is to provide a new public key framework which reduces the overheads of computation for digital signature generation/verification and communication for verifying the validity of X.509 certificate. Specially, we focus on developing new public key frameworks in Internet and Personal Area Network (PAN) environment.
For Internet environment, we review J. Zhou et al's public key framework from the view point of the actual deployment, and propose a new public key framework by changing security parameters into more suitable ones to enhance the actuality and reduce the overheads of computation and communication. Moreover, we analyze the security of our new public key framework from the vulnerability window point of view.
A PAN is the interconnection of fixed, portable, or moving components within a range of an individual operating space, typically within a range of 10 meters. In PAN the communication between components should be secure and authenticated since private information and personal data will be transmitted over radio links. Secure and authenticated communication can be achieved by means of proper security protocols and appropriate security associations among PAN components. For the sake of supporting key management in a PAN, a personal CA in the personal PKI concept is responsible for generating public key certificates for all mobile devices within the PAN. The personal CA is used by an ordinary user at home or small office deployment distinguished from large scale or global CA functions. Although the personal PKI concept seems to be properly applied to PAN environment, the adaptation of PKI concept to PAN is not suitable due to the limited resource of the mobile devices.
For PAN environment, we propose a new public key framework that reduces computational overheads for generating and verifying signatures on mobile devices. Especially. we focus on eliminating the traditional public key operations on mobile devices by means of one-time signature scheme, and differentiating it from previously proposed server-assisted signatures relied on assistances of a signature server. As a result, the proposed protocol gets rid of inherent drawbacks of server-assisted signatures such as problematic disputes, and high computational and storage requirements on the server side. Moreover, our framework provides simplified procedure for certificate status management based on hash chain to alleviate communication and computational costs for checking certificate status information.
- Author(s)
- 장화식
- Issued Date
- 2007
- Awarded Date
- 2007. 8
- Type
- Dissertation
- Keyword
- 공개키기반구조 개인영역네트워크 인증서 상태정보 PAN
- Publisher
- 부경대학교 대학원
- URI
- https://repository.pknu.ac.kr:8443/handle/2021.oak/3831
http://pknu.dcollection.net/jsp/common/DcLoOrgPer.jsp?sItemId=000001953786
- Alternative Author(s)
- Jang, Hwa-Sik
- Affiliation
- 부경대학교 대학원
- Department
- 대학원 정보공학과
- Advisor
- 이경현
- Table Of Contents
- 1. 서론 = 1
2. 공개키 기반구조 및 인증서 상태 검증 기술 = 5
2.1 공개키 기반구조 = 7
2.2 공개키 기반구조 구성 형태 = 10
2.3 인증서 상태 검증 기술 = 14
2.4 요약 = 20
3. PAN 및 Personal PKI = 22
3.1 PAN의 구조 = 22
3.2 Personal PKI = 24
3.3 인증서 관리 = 27
3.4 수동 인증 = 31
3.5 요약 = 37
4. 새로운 공개키 프레임워크 = 39
4.1 Zhou의 공개키 프레임워크 취약성 분석 = 39
4.2 새로운 공개키 프레임워크 제안 = 47
4.3 보안성 및 성능분석 = 49
4.4 요약 = 56
5. PAN 환경에서의 효율적인 공개키 프레임워크 = 57
5.1 암호 프리미티브 = 59
5.2 제안 시스템 모델 = 62
5.3 시스템 동작 = 66
5.4 보안성 및 성능 평가 = 70
5.5 요약 = 74
6. 결론 = 76
참고문헌 = 78
- Degree
- Doctor
-
Appears in Collections:
- 대학원 > 기타 학과
- Authorize & License
-
- Files in This Item:
-
Items in Repository are protected by copyright, with all rights reserved, unless otherwise indicated.