Title :
An Efficient Authentication and Access Control Scheme Using Smart Cards
Author :
Chen, Yen-Cheng ; Yeh, Lo-Yao
Author_Institution :
Dept. of Inf. Manage., Nat. Chi Nan Univ., Nantou
Abstract :
In this paper, we propose a novel integrated authentication and access control scheme using smart cards. A list of accessible resources with privileges is encrypted in the smart card issued to the user. Without storing access control information, a server can authenticate each user, realize resources to be accessed, and determine access privileges. We propose the use of card identifiers to prevent privilege elevation attacks and to protect the privacy of access requests. Our scheme has the following merits: low communication and computational cost, no access control information in the server, prevention of privilege elevation attack, multiple-access requests, privacy protection of access requests, mutual authentication, and session key agreement
Keywords :
authorisation; cryptography; message authentication; smart cards; access control scheme; access privileges; access request privacy; card identifiers; multiple-access requests; mutual authentication; privilege elevation attack prevention; session key agreement; smart cards; Access control; Authentication; Computational efficiency; Cryptography; Information management; Network servers; Privacy; Protection; Reflection; Smart cards;
Conference_Titel :
Parallel and Distributed Systems, 2005. Proceedings. 11th International Conference on
Conference_Location :
Fukuoka
Print_ISBN :
0-7695-2281-5
DOI :
10.1109/ICPADS.2005.80