A High Security Signature Algorithm Based on Kerberos for REST-style Cloud Storage Service

Yuanyuan Yang, Hui Li, Xiangdong Cheng, Xin Yang, Yaoguang Huo
{"title":"A High Security Signature Algorithm Based on Kerberos for REST-style Cloud Storage Service","authors":"Yuanyuan Yang, Hui Li, Xiangdong Cheng, Xin Yang, Yaoguang Huo","doi":"10.1109/UEMCON51285.2020.9298140","DOIUrl":null,"url":null,"abstract":"The Representational State Transfer (REST) is a distributed application architecture style which adopted on providing various network services. The identity authentication protocol Kerberos has been used to guarantee the security identity authentication of many service platforms. However, the deployment of Kerberos protocol is limited by the defects such as password guessing attacks, data tampering, and replay attacks. In this paper, an optimized Kerberos protocol is proposed and applied in a REST-style Cloud Storage Architecture. Firstly, we propose a Lately Used Newly (LUN) key replacement method to resist the password guessing attacks in Kerberos protocol. Secondly, we propose a formatted signature algorithm and a combination of signature string and time stamp method to cope with the problems of tampering and replay attacks which in deploying Kerberos. Finally, we build a security protection module using the optimized Kerberos protocol to guarantee a secure identity authentication and the reliable data communication between the client and the server. Analyses show that the module significantly improves the security of Kerberos protocol in REST-style cloud storage services.","PeriodicalId":433609,"journal":{"name":"2020 11th IEEE Annual Ubiquitous Computing, Electronics & Mobile Communication Conference (UEMCON)","volume":"9 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2020-10-28","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2020 11th IEEE Annual Ubiquitous Computing, Electronics & Mobile Communication Conference (UEMCON)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/UEMCON51285.2020.9298140","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

The Representational State Transfer (REST) is a distributed application architecture style which adopted on providing various network services. The identity authentication protocol Kerberos has been used to guarantee the security identity authentication of many service platforms. However, the deployment of Kerberos protocol is limited by the defects such as password guessing attacks, data tampering, and replay attacks. In this paper, an optimized Kerberos protocol is proposed and applied in a REST-style Cloud Storage Architecture. Firstly, we propose a Lately Used Newly (LUN) key replacement method to resist the password guessing attacks in Kerberos protocol. Secondly, we propose a formatted signature algorithm and a combination of signature string and time stamp method to cope with the problems of tampering and replay attacks which in deploying Kerberos. Finally, we build a security protection module using the optimized Kerberos protocol to guarantee a secure identity authentication and the reliable data communication between the client and the server. Analyses show that the module significantly improves the security of Kerberos protocol in REST-style cloud storage services.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
基于Kerberos的rest风格云存储服务高安全签名算法
REST (Representational State Transfer, Representational State Transfer)是一种用于提供各种网络服务的分布式应用程序架构风格。身份认证协议Kerberos已被用于许多业务平台的安全身份认证。但是,Kerberos协议的部署受到密码猜测攻击、数据篡改和重放攻击等缺陷的限制。本文提出了一种优化的Kerberos协议,并将其应用于rest风格的云存储架构中。首先,我们提出了一种新的LUN密钥替换方法来抵御Kerberos协议中的密码猜测攻击。其次,我们提出了一种格式化的签名算法和签名字符串与时间戳相结合的方法,以应对部署Kerberos时存在的篡改和重放攻击问题。最后,我们使用优化的Kerberos协议构建了一个安全保护模块,以保证客户端和服务器之间的安全身份验证和可靠的数据通信。分析表明,该模块显著提高了rest风格云存储服务中Kerberos协议的安全性。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Agile Edge Classification of Ocean Sounds EMG-based Hand Gesture Recognition by Deep Time-frequency Learning for Assisted Living & Rehabilitation A High Security Signature Algorithm Based on Kerberos for REST-style Cloud Storage Service A Comparison of Blockchain-Based Wireless Sensor Network Protocols Computer Vision based License Plate Detection for Automated Vehicle Parking Management System
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1