跳到主要內容

臺灣博碩士論文加值系統

(216.73.217.7) 您好!臺灣時間:2026/09/14 18:46
字體大小: 字級放大   字級縮小   預設字形  
回查詢結果 :::

詳目顯示

我願授權國圖
: 
twitterline
研究生:游立安
研究生(外文):Yu, Li-An
論文名稱:植基於橢圓曲線密碼學的群組通訊安全系統
論文名稱(外文):Group Communication Security System Based on Elliptic Curve Cryptography
指導教授:曾建超曾建超引用關係
指導教授(外文):Tseng, Chien-Chao
學位類別:博士
校院名稱:國立交通大學
系所名稱:網路工程研究所
學門:工程學門
學類:電資工程學類
論文種類:學術論文
論文出版年:2013
畢業學年度:102
語文別:中文
論文頁數:45
中文關鍵詞:群組通訊橢圓曲線密碼學預先共享金鑰認證金鑰廢止通訊金鑰
外文關鍵詞:Group CommunicationPre-shared key authenticationElliptic curve diffie-hellmanFuzzy identity-based encryptionAESKey revocationSession key
相關次數:
  • 被引用被引用:0
  • 點閱點閱:405
  • 評分評分:
  • 下載下載:0
  • 收藏至我的研究室書目清單書目收藏:0
現今有許多新興的應用程式建立在群組通訊的模組上,例如: 車載網路即時通訊、視訊會議或群組資料分享等應用。本論文以橢圓曲線密碼學為基礎,開發出一個群組通訊安全系統 (Group Communication Security System, GCSS)。此系統包含“群組成員的加入”、“一對多資料傳輸”、“一對一資料傳輸”與“群組成員的離開”的安全機制。在“群組成員加入”方面,GCSS利用預先共享金鑰認證以及橢圓曲線上的Diffie-Hellman金鑰交換協定,提供一套友善的成員加入機制與安全的金鑰分配。在“一對多資料分享”的應用,GCSS採用混合式密碼學系統來保護資料,以Fuzzy Identity-Based Cryptography (Fuzzy-IBE)提供精緻的存取控制,利用AES提供有效率的資料加密。在“一對一的資料分享”的應用,我們提出個人屬性金鑰協商協定(Individual-Attribute based Key Exchange protocol, IAKE)的機制,產生通訊金鑰,不需第三方的介入,就可達成成員之間安全的資料傳輸。此外,我們並針對“群組成員離開”,提出一個簡易的金鑰廢止機制,以確保成員離開後的群組通訊安全。
另外,本論文將IAKE與其他同類型的協定做比較,證明IAKE具有較好的安全性與較低的運算成本。我們也測試了GCSS在行動裝置上的效能,實驗結果也顯示,GCSS在行動裝置上的執行效能也極佳。

Many emerging applications, such as Instant Communication in Vehicular Networks and Video Conferencing, adopt group communication model. In this thesis, we use Elliptic Curve Cryptography (ECC) as the basis to develop a Group Communication Security System (GCSS). The GCSS system provides security mechanisms for “Group Member Join”, “One-to-Many Data Transmission”, “One-to-One Data Transmission” and “Group Member Leave”. In “Group Member Join”, GCSS integrates Pre-Shared Key (PSK) authentication with Elliptic Curve Diffie-Hellman (ECDH) key exchange protocol to provide user-friendly member join and secure key distribution. In “One-to-Many Data Transmission”, GCSS adopts hybrid cryptosystem to protect data transmission. It uses Fuzzy Identity-Based Encryption (Fuzzy-IBE) to provide granular access control and uses AES to provide efficient data encryption. In “One-to-One Data Transmission”, we propose an Individual-Attribute based Key Exchange (IAKE) protocol to generate session keys to enforce secure data transmission among members without the intervention of a third party. In “Group Member Leave”, a simple key revocation mechanism is proposed to assure the security of group communication after members leaving.
Comparing with other similar security mechanisms, IAKE can achieve better security with lower computation cost. Moreover, we have implemented GCSS on mobile devices. The experimental results show that GCSS is very effective on the mobile devices as well.

目錄
摘 要 I
Abstract II
誌謝 IV
表目錄 VIII
第一章、 緒論 1
1.1 研究動機 1
1.2 研究目的 3
1.3 論文架構 3
第二章、 背景知識 5
2.1 橢圓曲線密碼學 5
2.2 Bilinear Pairing 7
第三章、 相關研究 9
3.1認證協定(Authentication Protocol) 9
3.1.1 EAP-PSK Protocol 10
3.2 Attribute-Based Cryptography 12
3.2.1 Fuzzy Identity-Based Encryption 13
3.3 金鑰協商協定 (Key Agreement Protocol) 15
3.3.1 Elliptic Curve Diffie-Hellman Key Exchange Protocol 16
3.3.2 Identity-Based Key Agreement Protocol from Pairing 18
第四章、 Group Communication Security System 20
4.1 系統簡介 20
4.2 系統初始化 23
4.2.1 主密鑰與公開參數產生運算 24
4.3 群組成員加入 24
4.3.1 成員金鑰產生運算 27
4.4 一對多資料傳輸 27
4.4.1 通訊金鑰加密運算 28
4.4.2 通訊金鑰解密運算 28
4.5 一對一資料傳輸 29
4.5.1 Individual-Attribute based Key Exchange (IAKE) 30
4.6 成員金鑰廢止 33
4.6.1 成員金鑰更新運算 34
第五章、 安全分析與效能測試 35
5.1 IAKE安全分析 35
5.2 IAKE與其他協定比較 37
5.3 GCSS效能測試 38
第六章、 結論 42
6.1 研究成果 42
6.2 未來發展 42
參考文獻 43

[1] N. Koblitz, “Elliptic Curve Cryptosystems”, Mathematics of Computation, Vol.48, pp. 203-209, 1985.
[2] V. Miller, “Use of Elliptic Curve in Cryptography”, Advances in Cryptology-Crypto’85, Lecture Notes in Computer Science, Vol. 218, pp. 417-426, 1985.
[3] Chen, T.S., T.P. Liu, and Y. F. Chung., “A proxy-Protected Proxy Signature Scheme Based on Elliptic Curve Cryptosystem”, proceedings of IEEE TNECON’02, pp.184-187.
[4] A. Joux, “The Weil and Tate Pairing as Building for Public Key Cryptosystems”, in Proceeding Fifth Algorithmic Number Theory Symposium, Kecture Notes in Computer Science, Springer-Verlag, 2002.
[5] D. Boneh and M. Franklin, “Identity-Based Encryption from the Weil Pairing”, Advances in Cryptology-Crypto’01, LNCS 2139, pp. 213-229, Springer-Verlag, 2001.
[6] D. Boneh, B. Lynn and H. Shacham, “Short Signatures from the Weil Pairing”, Advances in Crytology-Asiacrypt’01, LNCS 2248, pp. 514-532, Springer, 2001
[7] L. Khermosh, “Managed Objects of Ethernet Passive Optical Networks (EPON)”, RFC 4837, July 2007.
[8] F. Bersani, France Telecom R&;D, H. Tschofenig, “The EAP-PSK Protocol: A Pre-Shared Key Extensible Authentication Protocol (EAP) Method”, RFC 4764, January 2007.
[9] NIST, “Advanced Encryption Standard (AES)”, Federal Information Processing Standards Publication 197, November 26, 2001.
[10] John Bethencourt, Amit Sahai, Brent Waters, “Ciphertext-Policy Attribute-Based Encryption”, in Proceedings of IEEE SP, Oakland, 2007.
[11] V. Goyal, O. Pandey, A. Sahai, and B. Waters. “Attribute Based Encryption for Fine-Grained Acess Control of Encrypted Data.” In ACM conference on Computer and Communications Security (ACM CCS), 2006.
[12] A. Sahai and B.Water. “Fuzzy Identity Based Encryption”, In Advances in Cryptology – Eurocrypt, volume 3494 of LNCS, pages 457-473. Springer, 2005.
[13] W. Diffie, M. Hellman, “New Direction in Cryptography”, IEEE Transactions on Information Theory, 22(6), pp. 644-654, 1976.
[14] ANSI X9.63, “Elliptic Curve Key Agreement and Key Transport Protocols”, American Bankers Association, 1999.
[15] L. Chen , “Z. Cheng , N. P. Smart, “Identity-Based Key Agreement Protocols from Pairings”, International Journal of Information Security, v.6 n.4, p.213-241, June 2007.
[16] A. Shamir, “Identity-Based Cryptosystems and Signature Schemes”, in Advances in Cryptology – Crypto’84, Springer-Verlag LNCS 196, 47-53, 1984.
[17] N. P. Smart, “Identity-Based Authenticated Key Agreement Protocol based on Weil Pairing”, Electronics Letters 39(8), 653-654, 2002.
[18] L. Chen and C. Kudla, “Identity Based Authenticated Key Agreement Protocols from pairing.”, in: Proc. 16th IEEE Security Foundations Workshop, pages 219 – 233, IEEE Computer Society Press, 2003.
[19] L. Chen and C. Kudla. Identity based authenticated key agreement from pairings. In IEEE Computer Security Foundations Workshop, 219–233, 2003. The modified version of this paper is available at Cryptology ePrint Archive, Report 2002/184.
[20] P. McCullagh and P. Barreto, “A New Two-Party Identity-Based Authenticated Key Agreement”, Proc. of CT-RSA 2005, pages 262-274, LNCS 3376, Springer Verlag, 2005.
[21] S. Li, Q. Yuan, and J. Li, “Towards Security Two-Part Authenticated Key Agreement Protocols.”, https://eprint.iacr.org/2005/300.pdf.
[22] Y. Choie, E. Jeong and E. Lee, “Efficient identity-based authenticated key agreement protocol from pairings”, Applied Mathematics and Computation, 162, 179–188, 2005.
[23] Q. Yuan and S. Li, “A new efficient ID-based authenticated key agreement protocol”, Cryptology ePrint Archive, Report 2005/309.
[24] E. Ryu, E. Yoon and K. Yoo, “An efficient ID-based authenticated key agreement protocol from pairings”, In Networking 2004, Springer-Verlag LNCS 3042, 1458–1463, 2004.
[25] C. Boyd, W. Mao and K. Paterson. Key agreement using statically keyed authenticators. In Applied Cryptography and Network Security: Second International Conference - ACNS Springer-Verlag LNCS 3089, 248–262, 2004.
[26] Y. Wang, “Efficient identity-based and authenticated key agreement protocol”, Cryptology ePrint Archive, Report 2005/108.
[27] “Java Pairing Based Cryptography”, Ben Lynn. Available: http://gas.dia.unisa.it/projects/jpbc/index.html, [Access: September, 16, 2013].
[28] “The Legion of the Bouncy Castle”. Available: http://www.bouncycastle.org/, [Access: September, 16, 2013]

連結至畢業學校之論文網頁點我開啟連結
註: 此連結為研究生畢業學校所提供,不一定有電子全文可供下載,若連結有誤,請點選上方之〝勘誤回報〞功能,我們會盡快修正,謝謝!
QRCODE
 
 
 
 
 
                                                                                                                                                                                                                                                                                                                                                                                                               
第一頁 上一頁 下一頁 最後一頁 top