Achieving communication effectiveness of web authentication protocol with key update

Zijian Zhang, Chongxi Shen, Liehuang Zhu*, Chen Xu, Salabat Khan Wazir, Chuyi Chen

*Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Today, with the presence of a large number of Man-In-The-Middle (MITM) attacks, identity authentication plays an important role in computer communication network. Series of authentication protocols have been proposed to resist against MITM attacks. Due to the lack of two-way certification between the client and the server, an attack named Man-In-The-Middle-Script-In-The-Browser (MITM-SITB) still works in most protocols. In order to protect against this kind of attack, a Channel-ID based authentication protocol named Server-Invariance-with-Strong-Client-Authentication (SISCA) is put forward. This protocol can not support key update and execute inefficiently. To solve this problem, we propose a Communication-Effectiveness-of-Web-Authentication (CEWA) protocol. We design a new certification process to make the protocol support key update, thus avoiding the risk of key leaks. Simultaneously, We designed the key storage method to manage the keys. We improve the efficiency of implementation. We also analyze its security and the experimental analysis shows the better performance of the efficiency than that in SISCA protocol.

Original languageEnglish
Title of host publicationMobile Ad-hoc and Sensor Networks - 13th International Conference, MSN 2017, Revised Selected Papers
EditorsLiehuang Zhu, Sheng Zhong
PublisherSpringer Verlag
Pages146-162
Number of pages17
ISBN (Print)9789811088896
DOIs
Publication statusPublished - 2018
Event13th International Conference on Mobile Ad-hoc and Sensor Networks, MSN 2017 - Beijing, China
Duration: 17 Dec 201720 Dec 2017

Publication series

NameCommunications in Computer and Information Science
Volume747
ISSN (Print)1865-0929

Conference

Conference13th International Conference on Mobile Ad-hoc and Sensor Networks, MSN 2017
Country/TerritoryChina
CityBeijing
Period17/12/1720/12/17

Keywords

  • Channel ID
  • Key update
  • Man-in-the-middle (MITM) attack
  • TLS
  • Web authentication

Fingerprint

Dive into the research topics of 'Achieving communication effectiveness of web authentication protocol with key update'. Together they form a unique fingerprint.

Cite this