An Efficient Authentication and Access Control Scheme Using Smart Cards

  • Authors:
  • Yen-Cheng Chen;Lo-Yao Yeh

  • Affiliations:
  • Department of Information Management, National Chi Nan University, Puli, Nantou 545, Taiwan;Department of Information Management, National Chi Nan University, Puli, Nantou 545, Taiwan

  • Venue:
  • ICPADS '05 Proceedings of the 11th International Conference on Parallel and Distributed Systems - Workshops - Volume 02
  • Year:
  • 2005

Quantified Score

Hi-index 0.00

Visualization

Abstract

In this paper, we propose a novel integrated authentication and access control scheme using smart cards. A list of accessible resources with privileges is encrypted in the smart card issued to the user. Without storing access control information, a server can authenticate each user, realize resources to be accessed, and determine access privileges. We propose the use of card identifiers to prevent privilege elevation attacks and to protect the privacy of access requests. Our scheme has the following merits: low communication and computational cost, no access control information in the server, prevention of privilege elevation attack, multiple-access requests, privacy protection of access requests, mutual authentication, and session key agreement.