基于QR码的多设备合作的安全端到端密钥交换机制

Yong Jin, M. Tomoishi
{"title":"基于QR码的多设备合作的安全端到端密钥交换机制","authors":"Yong Jin, M. Tomoishi","doi":"10.1109/ITNAC46935.2019.9078020","DOIUrl":null,"url":null,"abstract":"End-to-end key exchange for the subsequent secret sharing and secure communication between two remote parties has been an important issue due to the threats of eavesdropping and Man-In-The-Middle (MITM) attacks. In this paper, we propose a secure end-to-end key exchange mechanism between two remote parties by cooperation of multiple devices at each party using QR (Quick Response) codes. In the key exchange process, the data transmission will be conducted by two different applications via two different infrastructure networks, SMS (Short Message Service) via cellular network (e.g. LTE, 4G, etc) and Email via Ethernet respectively, between the two remote parties using two different devices at each party in order to mitigate security risks. Public-key cryptography will be adopted for the data transmission during the key exchange and the corresponding asymmetric key pair will be used only once. The data transmission within the multiple devices at each party only uses QR codes (scan and display) without involving any network based communication. The main contribution of this paper is that a novel secure end-to-end key exchange approach has been proposed in which unless both the devices using cellular network and Ethernet have been compromised or MITM attacked by the same attacker the key will not be leaked during the exchange process. We verified the main features of the proposed mechanism and confirmed the effectiveness of the design.","PeriodicalId":407514,"journal":{"name":"2019 29th International Telecommunication Networks and Applications Conference (ITNAC)","volume":"46 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2019-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"A Secure End-to-End Key Exchange Mechanism by Cooperation of Multiple Devices Using QR Codes\",\"authors\":\"Yong Jin, M. Tomoishi\",\"doi\":\"10.1109/ITNAC46935.2019.9078020\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"End-to-end key exchange for the subsequent secret sharing and secure communication between two remote parties has been an important issue due to the threats of eavesdropping and Man-In-The-Middle (MITM) attacks. In this paper, we propose a secure end-to-end key exchange mechanism between two remote parties by cooperation of multiple devices at each party using QR (Quick Response) codes. In the key exchange process, the data transmission will be conducted by two different applications via two different infrastructure networks, SMS (Short Message Service) via cellular network (e.g. LTE, 4G, etc) and Email via Ethernet respectively, between the two remote parties using two different devices at each party in order to mitigate security risks. Public-key cryptography will be adopted for the data transmission during the key exchange and the corresponding asymmetric key pair will be used only once. The data transmission within the multiple devices at each party only uses QR codes (scan and display) without involving any network based communication. The main contribution of this paper is that a novel secure end-to-end key exchange approach has been proposed in which unless both the devices using cellular network and Ethernet have been compromised or MITM attacked by the same attacker the key will not be leaked during the exchange process. We verified the main features of the proposed mechanism and confirmed the effectiveness of the design.\",\"PeriodicalId\":407514,\"journal\":{\"name\":\"2019 29th International Telecommunication Networks and Applications Conference (ITNAC)\",\"volume\":\"46 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2019-11-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2019 29th International Telecommunication Networks and Applications Conference (ITNAC)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/ITNAC46935.2019.9078020\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2019 29th International Telecommunication Networks and Applications Conference (ITNAC)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ITNAC46935.2019.9078020","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

摘要

由于窃听和中间人(MITM)攻击的威胁,为两个远程方之间后续的秘密共享和安全通信提供端到端密钥交换已经成为一个重要问题。在本文中,我们提出了一种安全的端到端密钥交换机制,通过每一方的多个设备使用QR(快速响应)码进行合作。在密钥交换过程中,数据传输将由两个不同的应用程序通过两个不同的基础设施网络进行,分别是通过蜂窝网络(例如LTE, 4G等)的SMS(短消息服务)和通过以太网的Email,在两个远程方之间使用每个方的两个不同设备,以减轻安全风险。密钥交换过程中的数据传输采用公开密钥加密,对应的非对称密钥对只使用一次。双方多台设备内的数据传输仅使用二维码(扫描显示),不涉及任何基于网络的通信。本文的主要贡献是提出了一种新的安全的端到端密钥交换方法,除非使用蜂窝网络和以太网的设备都被同一攻击者破坏或MITM攻击,否则密钥不会在交换过程中泄露。我们验证了所提出的机制的主要特征,并确认了设计的有效性。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
A Secure End-to-End Key Exchange Mechanism by Cooperation of Multiple Devices Using QR Codes
End-to-end key exchange for the subsequent secret sharing and secure communication between two remote parties has been an important issue due to the threats of eavesdropping and Man-In-The-Middle (MITM) attacks. In this paper, we propose a secure end-to-end key exchange mechanism between two remote parties by cooperation of multiple devices at each party using QR (Quick Response) codes. In the key exchange process, the data transmission will be conducted by two different applications via two different infrastructure networks, SMS (Short Message Service) via cellular network (e.g. LTE, 4G, etc) and Email via Ethernet respectively, between the two remote parties using two different devices at each party in order to mitigate security risks. Public-key cryptography will be adopted for the data transmission during the key exchange and the corresponding asymmetric key pair will be used only once. The data transmission within the multiple devices at each party only uses QR codes (scan and display) without involving any network based communication. The main contribution of this paper is that a novel secure end-to-end key exchange approach has been proposed in which unless both the devices using cellular network and Ethernet have been compromised or MITM attacked by the same attacker the key will not be leaked during the exchange process. We verified the main features of the proposed mechanism and confirmed the effectiveness of the design.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信