• DocumentCode
    1085739
  • Title

    Computationally Efficient PKI-Based Single Sign-On Protocol, PKASSO for Mobile Devices

  • Author

    Park, Ki-Woong ; Lim, Sang Seok ; Park, Kyu Ho

  • Author_Institution
    Dept. of Electr. Eng., KAIST, Daejeon
  • Volume
    57
  • Issue
    6
  • fYear
    2008
  • fDate
    6/1/2008 12:00:00 AM
  • Firstpage
    821
  • Lastpage
    834
  • Abstract
    In an attempt to expand Public Key Infrastructure (PKI) usage to a ubiquitous and mobile computing environment, we found that the deployment of the PKI on a resource-constrained device such as an 8-bit microprocessor leads to user-obstructive latency or additional circuitry for the operations. To alleviate these limitations, we propose a new PKI-based authentication protocol and security infrastructure, namely, PKASSO, which is enhanced with the single sign-on and delegation technology that is used especially for mobile devices with restricted computation power. PKASSO offloads complex PKI operations from the mobile devices to the infrastructure so as to keep the hardware and software complexity of the devices as low as possible. In addition, even though a conventional delegation mechanism cannot support a nonrepudiation mechanism against malicious user behavior, PKASSO can provide such a mechanism by devising a referee server that, on one hand, generates binding information between a device and authentication messages and, on the other hand, retains the information in its local storage for future accusation. We present the detailed design and performance evaluation of PKASSO and offer a protocol analysis in terms of user authentication latency and the completeness of the protocol. According to the performance evaluation, the authentication latency of our infrastructure (which averages 0.082 second) is much shorter than the authentication latency of a conventional PKI-based authentication latency (which averages 5.01 seconds).
  • Keywords
    cryptographic protocols; digital signatures; mobile computing; mobile radio; public key cryptography; telecommunication security; PKASSO infrastructure; PKI-based authentication protocol; delegation technology; message authentication latency; mobile computing; mobile device; performance evaluation; public key infrastructure; referee server; single sign-on protocol; Authentication; Circuits; Delay; Hardware; Microprocessors; Mobile computing; Pervasive computing; Protocols; Public key; Security; Authentication; Network-level security and protection;
  • fLanguage
    English
  • Journal_Title
    Computers, IEEE Transactions on
  • Publisher
    ieee
  • ISSN
    0018-9340
  • Type

    jour

  • DOI
    10.1109/TC.2008.36
  • Filename
    4459312