• DocumentCode
    3608878
  • Title

    Secure control protocol for universal serial bus mass storage devices

  • Author

    Jianghong Wei ; Wenfen Liu ; Xuexian Hu

  • Author_Institution
    State Key Lab. of Math. Eng. & Adv. Comput., Zhengzhou, China
  • Volume
    9
  • Issue
    6
  • fYear
    2015
  • Firstpage
    321
  • Lastpage
    327
  • Abstract
    The universal serial bus (USB) has some advantages like high transmission speed, plug-and-play and hot swapping, and has become the most popular interface standard for peripheral connections. However, such features also make it easier for a malicious user to extract confidential files from computer systems via USB ports. Consequently, to control the potential security risks of USB interface, many workplace and commercial corporations have directly forbidden their employees from using USB devices. To provide a flexible way of using USB without compromising security, this study proposes a novel secure control protocol for USB storage devices. The device and the server are required to complete mutual authentication and establish a session key used to encrypt the transferred files. The details of each phase of the new protocol are given. Security analysis demonstrates that the proposed protocol conquers those security pitfalls existing in the available protocols and can resist various attacks. Performance discussion indicates that the new protocol is also efficient enough for practical applications.
  • Keywords
    authorisation; cryptography; field buses; USB interface; USB ports; USB storage devices; commercial corporations; computer systems; confidential file extraction; hot swapping; interface standard; malicious user; mutual authentication; peripheral connections; plug-and-play; potential security risk control; secure control protocol; transferred file encryption; transmission speed; universal serial bus mass storage devices; workplace corporations;
  • fLanguage
    English
  • Journal_Title
    Computers Digital Techniques, IET
  • Publisher
    iet
  • ISSN
    1751-8601
  • Type

    jour

  • DOI
    10.1049/iet-cdt.2014.0196
  • Filename
    7303988