Title :
Design of secure FTP system
Author :
Xia, Liu ; Chao-sheng, Feng ; Ding, Yuan ; Can, Wang
Author_Institution :
Sch. of Comput. Sci., Sichuan Normal Univ., Chengdu, China
Abstract :
As a kind of protocol for transferring files, the File Transferring Protocol (FTP) has already been widely used for many years. However, there exist some secure vulnerabilities in the protocol. For example, both passwords and files are transmitted in plaintext. Although some new FTPs such as FTPS have been proposed and applied to overcome these vulnerabilities, there are many drawbacks such as lack of flexibility in use, failing to meet specific security requirements, etc. Given these facts, the FTP and its requirements are studied deeply and a new secure FTP system is designed in this paper. In the new system, a dynamic password mechanism is combined with smart card technology to achieve mutual authentication, key distribution and secure information transmission. The security level selection mechanism is adopted to meet individual security requirements. The resource access control mechanism is used to keep the server from unauthorized access attacks. Analysis shows that compared with existing FTP systems, the new system makes not only data transmission securer but also system in use easier, more flexible and efficient.
Keywords :
authorisation; protocols; dynamic password mechanism; file transferring protocol; key distribution; mutual authentication; resource access control mechanism; secure FTP system; secure information transmission; security level selection; security requirements; smart card technology; Cryptography; Servers;
Conference_Titel :
Communications, Circuits and Systems (ICCCAS), 2010 International Conference on
Conference_Location :
Chengdu
Print_ISBN :
978-1-4244-8224-5
DOI :
10.1109/ICCCAS.2010.5582002