跳到主要內容

臺灣博碩士論文加值系統

(216.73.216.60) 您好!臺灣時間:2026/08/01 16:17
字體大小: 字級放大   字級縮小   預設字形  
回查詢結果 :::

詳目顯示

我願授權國圖
: 
twitterline
研究生:邱信富
研究生(外文):Hsien-Fu Chiou
論文名稱:兼具使用者認證之有效率的電子訂閱系統
論文名稱(外文):An Efficient and Secure Electronic Subscription System with User Authentication
指導教授:曹偉駿曹偉駿引用關係
指導教授(外文):Woei-Jiunn Tsaur
學位類別:碩士
校院名稱:大葉大學
系所名稱:資訊管理學系碩士班
學門:電算機學門
學類:電算機一般學類
論文種類:學術論文
論文出版年:2001
畢業學年度:89
語文別:中文
論文頁數:61
中文關鍵詞:橢圓曲線密碼系統自我認證公開金鑰密碼系統公平交換協定存取控制使用者認證
外文關鍵詞:Elliptic curve cryptosystemsSelf-certified public key cryptosystemsFair exchange protocolAccess controlUser authentication
相關次數:
  • 被引用被引用:0
  • 點閱點閱:157
  • 評分評分:
  • 下載下載:0
  • 收藏至我的研究室書目清單書目收藏:2
預期日後的出版型態,將是平面與電子版本同歩發行的局面,基於「使用者付費」的原則,本論文提出一電子訂閱系統,使得使用者可依其需要或興趣,付費購買部分電子刊物的閱讀權利。本論文整合存取控制機制、橢圓曲線密碼系統與自我認證公開金鑰密碼系統的安全特性,並結合公平交換協定,來建構一個安全的電子訂閱環境。本論文所提出的電子訂閱系統具有下列優點:
1.使用者和出版商之間可以不必依靠公正的第三單位所簽發的數位憑證以驗證彼此的身分。
2.植基於橢圓曲線密碼系統的安全特性,以更少的位元數來達到相同的安全等級。
3.運用公平交換的原理,處理使用者訂閱的相關資訊,以維護雙方權益。
4.不論訂閱期限的長短,訂閱者只需保有一把秘密金鑰,系統即能判別所有訂閱期之刊物的使用權限。
5.當訂閱者的訂閱期限到期時,秘密金鑰即自動失效,換言之逾期的秘密金鑰會失去閱讀刊物的權利。
6.本電子訂閱系統能夠防止攻擊者的偽冒及重送攻擊。

We anticipate the publishing way in the future will be that the lithographic book and the electronic one coexist. Based on the principle of "usage-based payment", the thesis develops an electronic subscription system permitting users to pay for the rights of reading part of electronic periodicals according to his/her need or interest. In the thesis we integrate the security of access control, elliptic curve cryptosystems and self-certified public key cryptosystems with the fair exchange protocol to construct a secure electronic subscription environment. The electronic subscription system proposed in this thesis possesses the following advantages:
1.A user and the publisher can authenticate each other without verifying signature signed by TTP (Trusted Third Party) in their digital certificates.
2.Based on the security of elliptic curve cryptosystems, the proposed electronic subscription system can possess fewer bits achieving the same security degree as other public key cryptosystems.
3.According to the approach of the proposed fair exchange protocol, the electronic subscription system can prevent a dispute about the transaction between users and the publisher.
4.Regardless of users’ subscription periods, they all keep only a secret key, and the publisher can authenticate their reading privilege easily.
5.When a user’s subscripting date has expired, the function of his/her secret key can be terminated automatically. In other word, his/her secret key has no reading rights anymore.
6.The proposed electronic subscription system can prevent impersonation attack and the replay attack.

授權書iii
中文摘要v
英文摘要vi
誌謝viii
目錄ix
圖目錄xi
表目錄xii
第一章 緒 論 1
1.1 研究背景與動機 1
1.2 研究目的 3
1.3 研究架構 4
1.4 論文架構 6
第二章 文獻探討 7
2.1 電子商務安全需求 7
2.2 電子書 11
2.3 密碼學背景 14
2.4 公開金鑰密碼系統 17
2.4.1 憑證為基礎的公開金鑰密碼系統 18
2.4.2 身份為基礎的公開金鑰密碼系統 18
2.4.3 自我驗證公開金鑰密碼系統 19
2.4.4 橢圓曲線公開金鑰密碼系統 24
2.5 公平交換協定 29
2.5.1 On-line TTP 29
2.5.2 Off-line TTP 31
2.6 存取控制機制 33
第三章 兼具使用者認證之電子訂閱系統 36
3.1 植基於自我認證公開金鑰密碼系統的公平交換協定CEMBS 36
3.2 安全電子訂閱系統之設計 40
第四章 安全及複雜度分析 44
4.1 安全性分析 44
4.2 計算複雜度分析 47
4.3 資料傳輸量分析 51
第五章 結論與建議 54
參考文獻 56
附錄一:PEDLDLL憑證 61

[1]余千智,「電子商務總論」,智勝出版社,民國88年4月。
[2]胡國新,「設計植基於自我驗證公開金鑰系統之安全線上電子拍賣機 制」,大葉大學資訊管理研究所碩士論文,民國89年。(指導教授:曹偉駿)
[3]賴溪松、韓亮、張真誠,「近代密碼學及其應用」,松崗圖書資料公司,民國88年8月。
[4]鍾振華,「使用身分基礎之自我驗證公開金鑰的金鑰分配及會議金鑰分配技術」,台灣科技大學資訊管理研究所碩士論文,民國88年。(指導教授:吳宗成)
[5]黃裕峰,「應用密碼理論製作之電子刊物安全訂閱系統」,台灣工業技術學院管理技術研究所碩士論文,民國86年。(指導教授:吳宗成)
[6]林祝興、李正隆,“Elliptic-curve undeniable signature schemes,” 第11屆全國資訊安全會議,第331-338頁,民國90年5月。
[7]CCITT Recommendation X.509, “The Directory: Authentication Framework,” Jan 1997.
[8]V. S. Miller, “Use of elliptic curve in cryptography,” Advances in Cryptology: Crypto’85, 1985, pp. 417-426.
[9]B. S. Kaliski, “An overview of the PKCS standards,” RSA Laboratories, Nov. 1993.
[10]C. Gunther, “An identity-based key-exchange protocol,” Advances in Cryptology EuroCrypt ‘91, Lecture Notes in Computer Science, Vol. 547, Springer-Verlag, 1991, pp.29-37.
[11]C. P. Schnorr, “Efficient identification and signatures for smart cards,” Advances in Cryptology: Crypto’89, 1989, pp.339-351.
[12]E. Blham and A. Shamir, “Differential cryptanalysis of the data encryption standard,” Springer-Verlag, Berlin, 1993.
[13]F. Bao, R. Deng, and W. Mao, “Efficient and practical fair exchange protocols with off-line TTP,” Proceedings of the IEEE Symp. On Security and Privacy, Oakland, CA, May 3-6, 1998, pp. 77-85.
[14]H. Petersen, and P. Horster, “Self-certified keys concepts and applications,” Proceedings of Communications and Multimedia Security’97, 1997, pp. 102-116.
[15]Jurisic and A. J. Menezes, “Elliptic curves and cryptography,” Dr. Dobb’s Journal, 1997, pp. 26-35.
[16]C. H. Lin, “Dynamic key management schemes for access control in a hierarchy,” Computer Communications, Vol.20, Dec 15, 1997, pp.1381-1385.
[17]M. Girault, “Self-certified public keys,” Advances in Cryptology: EuroCrypt’91, Lecture Notes in Computer Science, Vol. 547, Springer-Verlag, 1991,4 pp. 491-497.
[18]M. K. Franklin and M. K. Reiter, “Fair exchange with a semi-trusted third party,” Proceedings of the 4th ACM Conferences on Computer and Communications Security, April 1-4, 1997,pp. 1-5.
[19]M. Stadler, “Publicly verifiable secret sharing”, Proceedings of Eurocrypto’96, LNCS 1070, Springer-Verlag, 1996, pp. 190-199.
[20]MasterCard and VISA, “Secure electronic transaction specification,” June 1996.
[21]N. Asokan, M. Schunter and M. Waidner, “Optimistic protocols for fair exchange,” Proceedings of the 4th ACM Conferences on Computer and Communications Security, April 1997, pp. 6-17.
[22]N. Asokan, V. Shoup and M. Waidner, “Asynchronous protocols for optimistic fair exchange,” Proceedings of the IEEE Symp. On Security and Privacy, Oakland, CA, May 3-6, 1998, pp. 86-100.
[23]N. Koblitz, “Elliptic curve cryptosystems,” Mathematics of Computation, Vol. 48, No. 17, 1987, pp. 203-209.
[24]N. Zhang, Q. Shi and M. Merabti, “A flexible approach to secure and fair document exchange,” The Computer Journal, Vol.42, No 7, 1999, pp. 569-581.
[25]“Proposed federal information processing standard for digital signature standard,” Federal Register, Vol. 56, No.169, Aug.30, 1991, pp. 42980-42982.
[26]R. Rivest, “The MD5 message digest algorithm,” RFC 1321, 1992.
[27]R. Rivest, A. Shamir and L. Adleman, “A method for obtaining digital signatures and public-key cryptosystems, ” Communications of the ACM, Vol. 21, No. 2, Feb. 1978, pp. 120-126.
[28]S. Kim, S. Oh, S. Park and D. Won, “On Saeednia’s key-exchange protocols,” KICS (Korean Institute of Communication Sciences) Conference, Vol. 17, No. 2, Korea, 1998, pp.1001-1004.
[29]S. Saeednia, “Identity-based and self-certified key-exchange protocols,” Information Security and Privacy: ACISP’97, 1997, pp. 303-313.
[30]S. Vanstone, “Elliptic curve cryptosystem-the answer to strong, fast public-key cryptography for securing constrained environments,” Information Security Technical Report, Vol. 2, No. 2, 1997, pp. 78-87.
[31]Shamir, “Identity-based cryptosystems and signature schemes,” Advances in Cryptology: Crypto’84, 1984, pp. 47-53.
[32]T. ElGamal, “A public key cryptosystem and a signature scheme based on discrete logarithms, ”IEEE Transactions on Information Theory, Vol. IT-31, No. 4, 1985, pp. 469-472.
[33]T. C. Wu, Y.S. Chang, and T.Y. Lin, “Improvement of Saeednia’s self-certified key exchange protocols, ”IEE Electronic Letters, Vol 34, No 11, May 1998, pp. 1094-1095.
[34]T. C. Wu, “Digital signature/multisignature schemes giving public key verification and message recovery simultaneously,” to appear in Computer Systems Science and Engineering, 2001.
[35]“The digital signature standard proposed by NIST,” Commun. ACM, Vol.35, No7, July 1992, pp. 41-54.
[36]H. M. Tsai and C. C. Chang, “A cryptographic implementation for dynamic access control in a user hierarchy,” Computer and Security, Vol. 14,No. 2, 1995, pp.159-166.
[37]W. Caelli, E. Dawson, and S. Rea, “PKI, elliptic curve cryptography and digital signatures,” Computer and Security, Vol. 18, No. 1, 1999, pp. 47-66.
[38]W. Diffie and M. E. Hellman, “New directions in cryptography, ”IEEE Transactions on Information Theory, Vol. IT-22, No. 6, 1976, pp. 644-654.
[39]Y. S. Chang, T. C. Wu, and S. C. Huang, “ElGamal-like digital signature and multisignature schemes using self-certified public keys,” The Journal of System and Software, 2000, pp. 99-105.
[40]http://www.ehanism.com.tw/
[41]http://www.silkbook.net/
[42]http://www.zdnet.com/
[43]http://www.rocketbook.com/
[44]http://www.softbook.com/
[45]http://www.bookinsight.com.tw/
[46]http://www.digiebooks.com/
[47]D. B. Johnson and A. J. Menezes, “ECDSA: An Enhanced DSA”, http://www.certicom.com

QRCODE
 
 
 
 
 
                                                                                                                                                                                                                                                                                                                                                                                                               
第一頁 上一頁 下一頁 最後一頁 top