Richa Garg, Mayank Gupta, Ruhul Amin, Kalgi Patel, S. H. Islam, G. P. Biswas
{"title":"基于SOCKS V5的手机VPN安全认证协议设计","authors":"Richa Garg, Mayank Gupta, Ruhul Amin, Kalgi Patel, S. H. Islam, G. P. Biswas","doi":"10.1109/ITACT.2015.7492654","DOIUrl":null,"url":null,"abstract":"The Socket Secure version 5 (SOCKS V5) protocol described the password-based authentication to provide authentication services to the initial SOCKS protocol. In this approach, the request transmits the password in plaintext and thus, it is not recommended due to security reasons. In this article, we proposed a mobile phone-based authentication with session key agreement approach that provides strong authentication services to SOCKS V5 protocol. The protocol is suitable for mobile users and makes use of International Mobile Subscriber Identity (IMSI) to provide unique identification. In this protocol, mobile phone is used to provide authentication between user and SOCKS proxy server when a user wants to access a Virtual Private Network (VPN). Easy availability and widely acceptance of mobile phones in comparison to smart cards is the motivation behind developing this authentication protocol. The proposed protocol establishes the session keys between mobile user and SOCKS proxy server as well as Application Server of the VPN. In the proposed protocol, multiple mobile users can simultaneously access the application server via a SOCKS proxy server. The proposed protocol is secure against known attacks.","PeriodicalId":336783,"journal":{"name":"2015 International Conference on Trends in Automation, Communications and Computing Technology (I-TACT-15)","volume":"6 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2015-12-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":"{\"title\":\"Design of secure authentication protocol in SOCKS V5 for VPN using mobile phone\",\"authors\":\"Richa Garg, Mayank Gupta, Ruhul Amin, Kalgi Patel, S. H. Islam, G. P. Biswas\",\"doi\":\"10.1109/ITACT.2015.7492654\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"The Socket Secure version 5 (SOCKS V5) protocol described the password-based authentication to provide authentication services to the initial SOCKS protocol. In this approach, the request transmits the password in plaintext and thus, it is not recommended due to security reasons. In this article, we proposed a mobile phone-based authentication with session key agreement approach that provides strong authentication services to SOCKS V5 protocol. The protocol is suitable for mobile users and makes use of International Mobile Subscriber Identity (IMSI) to provide unique identification. In this protocol, mobile phone is used to provide authentication between user and SOCKS proxy server when a user wants to access a Virtual Private Network (VPN). Easy availability and widely acceptance of mobile phones in comparison to smart cards is the motivation behind developing this authentication protocol. The proposed protocol establishes the session keys between mobile user and SOCKS proxy server as well as Application Server of the VPN. In the proposed protocol, multiple mobile users can simultaneously access the application server via a SOCKS proxy server. The proposed protocol is secure against known attacks.\",\"PeriodicalId\":336783,\"journal\":{\"name\":\"2015 International Conference on Trends in Automation, Communications and Computing Technology (I-TACT-15)\",\"volume\":\"6 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2015-12-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"2\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2015 International Conference on Trends in Automation, Communications and Computing Technology (I-TACT-15)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/ITACT.2015.7492654\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2015 International Conference on Trends in Automation, Communications and Computing Technology (I-TACT-15)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ITACT.2015.7492654","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2
摘要
Socket Secure version 5 (SOCKS V5)协议描述了基于密码的身份验证,为初始的SOCKS协议提供身份验证服务。在这种方法中,请求以明文方式传输密码,因此出于安全考虑,不建议使用这种方法。本文提出了一种基于移动电话的会话密钥协议身份验证方法,为SOCKS V5协议提供了强大的身份验证服务。该协议适用于移动用户,利用国际移动用户标识(IMSI)提供唯一标识。在该协议中,当用户需要访问VPN (Virtual Private Network)时,使用手机在用户和SOCKS代理服务器之间提供身份验证。与智能卡相比,移动电话的易用性和广泛接受性是开发这种身份验证协议背后的动机。该协议建立了移动用户与SOCKS代理服务器以及VPN的应用服务器之间的会话密钥。在提出的协议中,多个移动用户可以同时通过SOCKS代理服务器访问应用服务器。提议的协议对于已知的攻击是安全的。
Design of secure authentication protocol in SOCKS V5 for VPN using mobile phone
The Socket Secure version 5 (SOCKS V5) protocol described the password-based authentication to provide authentication services to the initial SOCKS protocol. In this approach, the request transmits the password in plaintext and thus, it is not recommended due to security reasons. In this article, we proposed a mobile phone-based authentication with session key agreement approach that provides strong authentication services to SOCKS V5 protocol. The protocol is suitable for mobile users and makes use of International Mobile Subscriber Identity (IMSI) to provide unique identification. In this protocol, mobile phone is used to provide authentication between user and SOCKS proxy server when a user wants to access a Virtual Private Network (VPN). Easy availability and widely acceptance of mobile phones in comparison to smart cards is the motivation behind developing this authentication protocol. The proposed protocol establishes the session keys between mobile user and SOCKS proxy server as well as Application Server of the VPN. In the proposed protocol, multiple mobile users can simultaneously access the application server via a SOCKS proxy server. The proposed protocol is secure against known attacks.