PUKYONG

새로운 공개키 프레임워크와 PAN을 위한 응용

Metadata Downloads
Alternative Title
A New Public Key Framework and its Applications to PAN
Abstract
Without doubt, the promise of Public Key Infrastructure (PKI) technology has attracted a significant amount of attention to support secure and authenticated services in the heterogeneous networks. The IETF PKIX Working Group is developing the Internet standards to support an X.509-based PKI, which provides a framework on services related to issuing public key certificates and distributing revocation information. The lack of a mechanism that provides efficient and timely distribution of certification revocatino information is a main issue for implementing more efficient PKI environment. The existing certificate revocation schemes place a considerable processing. commucication. and storage overheads on certificate authority(CA) as well as the relying parties.
In this thesis, the main target of our research is to provide a new public key framework which reduces the overheads of computation for digital signature generation/verification and communication for verifying the validity of X.509 certificate. Specially, we focus on developing new public key frameworks in Internet and Personal Area Network (PAN) environment.
For Internet environment, we review J. Zhou et al's public key framework from the view point of the actual deployment, and propose a new public key framework by changing security parameters into more suitable ones to enhance the actuality and reduce the overheads of computation and communication. Moreover, we analyze the security of our new public key framework from the vulnerability window point of view.
A PAN is the interconnection of fixed, portable, or moving components within a range of an individual operating space, typically within a range of 10 meters. In PAN the communication between components should be secure and authenticated since private information and personal data will be transmitted over radio links. Secure and authenticated communication can be achieved by means of proper security protocols and appropriate security associations among PAN components. For the sake of supporting key management in a PAN, a personal CA in the personal PKI concept is responsible for generating public key certificates for all mobile devices within the PAN. The personal CA is used by an ordinary user at home or small office deployment distinguished from large scale or global CA functions. Although the personal PKI concept seems to be properly applied to PAN environment, the adaptation of PKI concept to PAN is not suitable due to the limited resource of the mobile devices.
For PAN environment, we propose a new public key framework that reduces computational overheads for generating and verifying signatures on mobile devices. Especially. we focus on eliminating the traditional public key operations on mobile devices by means of one-time signature scheme, and differentiating it from previously proposed server-assisted signatures relied on assistances of a signature server. As a result, the proposed protocol gets rid of inherent drawbacks of server-assisted signatures such as problematic disputes, and high computational and storage requirements on the server side. Moreover, our framework provides simplified procedure for certificate status management based on hash chain to alleviate communication and computational costs for checking certificate status information.
Author(s)
장화식
Issued Date
2007
Awarded Date
2007. 8
Type
Dissertation
Keyword
공개키기반구조 개인영역네트워크 인증서 상태정보 PAN
Publisher
부경대학교 대학원
URI
https://repository.pknu.ac.kr:8443/handle/2021.oak/3831
http://pknu.dcollection.net/jsp/common/DcLoOrgPer.jsp?sItemId=000001953786
Alternative Author(s)
Jang, Hwa-Sik
Affiliation
부경대학교 대학원
Department
대학원 정보공학과
Advisor
이경현
Table Of Contents
1. 서론 = 1
2. 공개키 기반구조 및 인증서 상태 검증 기술 = 5
2.1 공개키 기반구조 = 7
2.2 공개키 기반구조 구성 형태 = 10
2.3 인증서 상태 검증 기술 = 14
2.4 요약 = 20
3. PAN 및 Personal PKI = 22
3.1 PAN의 구조 = 22
3.2 Personal PKI = 24
3.3 인증서 관리 = 27
3.4 수동 인증 = 31
3.5 요약 = 37
4. 새로운 공개키 프레임워크 = 39
4.1 Zhou의 공개키 프레임워크 취약성 분석 = 39
4.2 새로운 공개키 프레임워크 제안 = 47
4.3 보안성 및 성능분석 = 49
4.4 요약 = 56
5. PAN 환경에서의 효율적인 공개키 프레임워크 = 57
5.1 암호 프리미티브 = 59
5.2 제안 시스템 모델 = 62
5.3 시스템 동작 = 66
5.4 보안성 및 성능 평가 = 70
5.5 요약 = 74
6. 결론 = 76
참고문헌 = 78
Degree
Doctor
Appears in Collections:
대학원 > 기타 학과
Authorize & License
  • Authorize공개
Files in This Item:

Items in Repository are protected by copyright, with all rights reserved, unless otherwise indicated.