{"title":"通过电子身份证进行业务认证:通过DNIe进行VoIP业务认证","authors":"Igor Ruiz-Agundez, P. G. Bringas","doi":"10.1109/SRII.2012.73","DOIUrl":null,"url":null,"abstract":"User authentication is one of the most popular techniques used in access control systems. It provides with trustful confirmation about the identity of a person when she attempts to use a service. It ensures that a user is who she claims to be verifying by that she is allowed to use a certain service. Different governments and agencies have attempted to create a universal authentication device to allow easy access to e-government services and potentially to any corporative service. Authentication contributes to the unequivocal identification of the user. In this research, we focus on the Spanish electronic identification card (also known as DNIe). In our research we focus on authentication through the DNIe because it provides with two levels of security. Authenticating with the DNIe implies having the electronic identification card (eID card) and knowing the card holder's verification password. We implement a methodology that integrates DNIe authentication in any application through a service library component seamlessly. This authentication methodology takes advantage of all the DNIe capabilities and includes the following steps: connection to the eID card, load of user certificates, generation of a verification challenge, signing and verification of this challenge by using cryptographic techniques, and finally, accepting or rejecting user identification. In order to validate this methodology, we integrate our seamless authentication library in a Voice over IP application. Currently, this methodology is being used in call-centres that need to unequivocally validate the identity of the operators in each call and operation they perform.","PeriodicalId":110778,"journal":{"name":"2012 Annual SRII Global Conference","volume":"86 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2012-07-24","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"4","resultStr":"{\"title\":\"Service Authentication via Electronic Identification Cards: VoIP Service Authentication through the DNIe\",\"authors\":\"Igor Ruiz-Agundez, P. G. Bringas\",\"doi\":\"10.1109/SRII.2012.73\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"User authentication is one of the most popular techniques used in access control systems. It provides with trustful confirmation about the identity of a person when she attempts to use a service. It ensures that a user is who she claims to be verifying by that she is allowed to use a certain service. Different governments and agencies have attempted to create a universal authentication device to allow easy access to e-government services and potentially to any corporative service. Authentication contributes to the unequivocal identification of the user. In this research, we focus on the Spanish electronic identification card (also known as DNIe). In our research we focus on authentication through the DNIe because it provides with two levels of security. Authenticating with the DNIe implies having the electronic identification card (eID card) and knowing the card holder's verification password. We implement a methodology that integrates DNIe authentication in any application through a service library component seamlessly. This authentication methodology takes advantage of all the DNIe capabilities and includes the following steps: connection to the eID card, load of user certificates, generation of a verification challenge, signing and verification of this challenge by using cryptographic techniques, and finally, accepting or rejecting user identification. In order to validate this methodology, we integrate our seamless authentication library in a Voice over IP application. Currently, this methodology is being used in call-centres that need to unequivocally validate the identity of the operators in each call and operation they perform.\",\"PeriodicalId\":110778,\"journal\":{\"name\":\"2012 Annual SRII Global Conference\",\"volume\":\"86 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2012-07-24\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"4\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2012 Annual SRII Global Conference\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/SRII.2012.73\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2012 Annual SRII Global Conference","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/SRII.2012.73","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 4
摘要
用户身份验证是访问控制系统中最常用的技术之一。当一个人试图使用一项服务时,它提供了关于其身份的可信确认。它确保用户是她声称要验证的人,她被允许使用某个服务。不同的政府和机构试图创建一种通用的身份验证设备,以便方便地访问电子政务服务和潜在的任何公司服务。身份验证有助于明确地识别用户。在本研究中,我们将重点放在西班牙电子身份证(也称为DNIe)上。在我们的研究中,我们主要关注通过DNIe进行身份验证,因为它提供了两个级别的安全性。使用DNIe进行身份验证意味着拥有电子身份证(eID卡)并知道持卡人的验证密码。我们实现了一种方法,通过服务库组件无缝地将DNIe身份验证集成到任何应用程序中。这种身份验证方法利用了所有DNIe功能,包括以下步骤:连接到eID卡、加载用户证书、生成验证挑战、使用加密技术对该挑战进行签名和验证,最后接受或拒绝用户标识。为了验证这种方法,我们将无缝身份验证库集成到Voice over IP应用程序中。目前,这种方法正在呼叫中心使用,这些呼叫中心需要在每次呼叫和他们执行的操作中明确验证操作员的身份。
Service Authentication via Electronic Identification Cards: VoIP Service Authentication through the DNIe
User authentication is one of the most popular techniques used in access control systems. It provides with trustful confirmation about the identity of a person when she attempts to use a service. It ensures that a user is who she claims to be verifying by that she is allowed to use a certain service. Different governments and agencies have attempted to create a universal authentication device to allow easy access to e-government services and potentially to any corporative service. Authentication contributes to the unequivocal identification of the user. In this research, we focus on the Spanish electronic identification card (also known as DNIe). In our research we focus on authentication through the DNIe because it provides with two levels of security. Authenticating with the DNIe implies having the electronic identification card (eID card) and knowing the card holder's verification password. We implement a methodology that integrates DNIe authentication in any application through a service library component seamlessly. This authentication methodology takes advantage of all the DNIe capabilities and includes the following steps: connection to the eID card, load of user certificates, generation of a verification challenge, signing and verification of this challenge by using cryptographic techniques, and finally, accepting or rejecting user identification. In order to validate this methodology, we integrate our seamless authentication library in a Voice over IP application. Currently, this methodology is being used in call-centres that need to unequivocally validate the identity of the operators in each call and operation they perform.