DocumentCode :
2408618
Title :
A denial-of-service resistant public-key authentication and key establishment protocol
Author :
Fung, Chun-Kan ; Lee, M.C.
Author_Institution :
Chinese Univ. of Hong Kong, Shatin, China
fYear :
2002
fDate :
2002
Firstpage :
171
Lastpage :
178
Abstract :
Network denial-of-service attacks, which exhaust the server resources, have become a serious security threat to the Internet. Public key infrastructure (PKI) has long been introduced in various authentication protocols to verify the identities of the communicating parties. Although the use of PKI can present difficulty to the denial-of-service attackers, the underlying problem has not been resolved completely, because the use of public-key infrastructure involves computationally expensive operations such as modular exponentiation. An improper deployment of the public-key operations in a protocol allows the attacker to exhaust the server´s resources. This paper presents a public-key based authentication and key establishment protocol integrated with a sophisticated client puzzle, which together provides a good solution for network denial-of-service attacks, and various other common attacks. The joint establishment of session keys by both the client and the server protects the session after the mutual authentication. The basic strategy to protect against denial of service is to impose an adjustable cost on the attacker while launching the attacks. The proposed client puzzle protocol can also be integrated with other network protocols to protect against denial-of-service attacks
Keywords :
Internet; client-server systems; message authentication; protocols; public key cryptography; Internet; PKI; authentication protocols; client puzzle protocol; client server system; denial-of-service attacks; key establishment protocol; mutual authentication; public-key authentication; security; Authentication; Computer crime; Costs; Cryptographic protocols; Cryptography; IP networks; Network servers; Protection; Public key; Web server;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Performance, Computing, and Communications Conference, 2002. 21st IEEE International
Conference_Location :
Phoenix, AZ
Print_ISBN :
0-7803-7371-5
Type :
conf
DOI :
10.1109/IPCCC.2002.995148
Filename :
995148
Link To Document :
بازگشت