Geri Dön

P/key: PUF based second factor authentication

P/anahtar: PUF tabanlı ikinci faktör kimlik doğrulama

  1. Tez No: 726730
  2. Yazar: ERTAN UYSAL
  3. Danışmanlar: DR. ÖĞR. ÜYESİ METE AKGÜN, DR. ÖĞR. ÜYESİ SERAP ŞAHİN
  4. Tez Türü: Yüksek Lisans
  5. Konular: Bilgisayar Mühendisliği Bilimleri-Bilgisayar ve Kontrol, Computer Engineering and Computer Science and Control
  6. Anahtar Kelimeler: Kimlik doğrulama, Parmak izi, Tek kullanımlık şifre, Şifreleme, Identification verify, Fingerprint, One-time password, Encryption
  7. Yıl: 2022
  8. Dil: İngilizce
  9. Üniversite: İzmir Yüksek Teknoloji Enstitüsü
  10. Enstitü: Lisansüstü Eğitim Enstitüsü
  11. Ana Bilim Dalı: Bilgisayar Mühendisliği Ana Bilim Dalı
  12. Bilim Dalı: Belirtilmemiş.
  13. Sayfa Sayısı: Belirtilmemiş.

Özet

Kimlik doğrulama işleminin güvenliğini arttırmak amacıyla tek faktöre yardımcı ek bir katman eklenerek iki faktörlü kimlik doğrulama mekanizmaları kullanılmaktadır. İkinci faktör olarak tek kullanımlık şifre (OTP) kullanımı donanım bağımsız, kolay üretilebilmesinden kaynaklı tercih edilir. OTP üreten protokolleri temel olarak iki kategoride değerlendirmek gerekir: zaman maliyeti ve güvenlik. Zamana dayalı OTP mekanizmalarında (TOTP) istemci ve sunucu ortak bir anahtar değer saklar. Ancak sunucu saldırganlar tarafından ele geçirilirse, saldırgan anahtar bilgisini kullanarak yeni OTP üretebilir ve istemci gibi davranıp sisteme erişim sağlayabilir. Bu sorunu çözmek amacıyla hash zinciri mekanizmasına dayalı çeşitli yöntemler önerilmiştir ancak bu yöntemler temel olarak kimlik doğrulama hızı ve limitli sayıda OTP ürettiklerinden dolayı zafiyetler içerir. Bu tez çalışmasında bu sorunların üstesinden gelmek amacıyla, sunucu tarafı saldırıya karşı güvenli ve hızlı yanıt veren fiziksel klonlanmayan fonksiyonlara (PUF) dayalı iki faktörlü kimlik doğrulama mekanizması öne sürüyoruz. PUF, cihazların üretim aşamalarındaki kontrol edilemeyen faktörler sebebiyle üretilen her cihazın benzersiz olmasını sağlayan dijital parmak izidir. Meydan okuma değerlerine karşı, cevaplar üretir. PUF yapısı cihazlardaki mikro seviyedeki farklılıklardan kaynaklandığı için saldırı durumunda mikro seviyede yapı değişir ve PUF farklı cevaplar üretmeye başlar. PUF hızlı cevap üreten bir fonksiyon olmasına karşı, ürettiği yanıttan girdi değerine ulaşmak imkansızdır. Önerilen protokolde, sunucunun içindeki PUF, anahtar değerleri üretir ve ayrıca istemcilerin gizli tohum değerlerini güvenli bir şekilde saklamak için kullanılır. Sunucu tarafında yan kanal saldırısı olması durumunda, PUF yapısı bozulacağı için istemcilerin anahtar değerleri saldırganlar tarafından elde edilemez. Saldırgan, sunucunun kimlik bilgilerini alıp sisteme erişim sağlasa bile, istemcilerin gizli tohum değerlerini alamaz ve bu değerleri kullanarak OTP oluşturamaz. Bu sayede, saldırgan istemcinin kimliğine bürünerek kimlik doğrulaması yapamaz.

Özet (Çeviri)

Second-factor authentication mechanisms increase the security of authentication processes by implementing an additional auxiliary layer to a single factor. As a second factor, using one-time passwords (OTP) is mainly preferred due to their hardware independence and easy generation. OTP generation protocols should be evaluated in two main categories: time and security. In time-based OTP mechanisms (TOTP), client and server store a shared secret key. However, if attackers compromise the server, attackers can generate new OTPs using the key and impersonate the client. To solve this problem, protocols based on the hash chain mechanism have been proposed; however, these methods have weaknesses mainly due to the authentication speed and the limited number of OTPs they generate. This thesis proposes a server-side tamper-proof and fast response physical unclonable function (PUF) based second-factor authentication protocol on overcoming these problems. PUF is a digital fingerprint that ensures that every device produced is unique due to uncontrollable factors in the production stages of devices. It generates responses that correspond to challenges. Since PUF is based on the micro-level differences in devices, micro-level structure changes in the event of an attack, and the PUF takes to generate different responses. Although PUF is a fast response function, it is impossible to reach the challenge from the response it generates. In the proposed protocol, the PUF inside the server generates key values and used to store clients' secret seed values securely. In case of side-channel attack on server-side, the key values of the clients cannot be obtained by the attackers, as the PUF structure will be corrupted. Even if the attacker obtains the server's credentials and gains access to the system, they cannot get the secret seed values of the clients and cannot generate the OTPs. In this way, the attacker cannot authenticate by impersonating the client.

Benzer Tezler

  1. Polimer ince filmlerdeki ıslatmama kararsızlıkları ile fiziksel olarak klonlanamayan fonksiyonların üretimi

    Fabrication of physically unclonable functions via dewetting of polymer thin films

    NESLİHAN TÖRÜN

    Yüksek Lisans

    Türkçe

    Türkçe

    2022

    Mühendislik BilimleriErciyes Üniversitesi

    Nanobilim ve Nanoteknoloji Ana Bilim Dalı

    PROF. DR. MUSTAFA SERDAR ÖNSES

    ÖĞR. GÖR. MENEKŞE ŞAKİR

  2. Kuru incirlerde küf florası ve aflatoksigenik küflerin saptanması

    Başlık çevirisi yok

    SİBEL BÜYÜKŞİRİN

    Yüksek Lisans

    Türkçe

    Türkçe

    1993

    BiyolojiEge Üniversitesi

    Biyoloji Bilim Dalı

    DOÇ. DR. İSMAİL KARABOZ

  3. Erişkinlerde salbutamolün sevofluran indüksiyonu hızına etkisi

    Başlık çevirisi yok

    NADİR ERDOĞAN

    Tıpta Uzmanlık

    Türkçe

    Türkçe

    2005

    Anestezi ve ReanimasyonHarran Üniversitesi

    Anesteziyoloji ve Reanimasyon Ana Bilim Dalı

    Y.DOÇ.DR. MUSTAFA CENGİZ

  4. Asemptomatik periton ve hemodiyaliz hastalarındaperikardiyal effüzyon sıklığı

    In patients with asymptomatic periton and hemodialysispericardial effusion frequency

    ŞÜKRİYE TAŞÇI KARAGÖL

    Tıpta Uzmanlık

    Türkçe

    Türkçe

    2012

    NefrolojiSağlık Bakanlığı

    Dahiliye Ana Bilim Dalı

    DR. ÖĞR. ÜYESİ CEVAT TOPAL

  5. Fenolik reçineleri bağlayıcı olarak kullanarak kok tozundan döküm koku ve metalürjik kok üretimi

    The Production of foundry coke and metallurgical coke from coke breeze by using fenolic resins as binder

    AYŞE BENK

    Doktora

    Türkçe

    Türkçe

    2001

    KimyaGazi Üniversitesi

    Kimya Ana Bilim Dalı

    PROF. DR. MUZAFFER TALU