Key Laboratory of Aerospace Information Security and Trusted Computing,Ministry of Education,School of Cyber Science and Engineering,Wuhan University,Wuhan 430072,Hubei,China
The current client authentication mainly has two methods: Transport Layer Security (TLS) and application-layer authentication methods based on TLS. The existing TLS protocol is widely used for server authentication, but its client authentication is less commonly enforced due to issues such as complex certificate management and vulnerability to attacks. Application-layer authentication has problems such as forgetfulness, single-point authentication, dependency on firmware, and poor compatibility. To solve these problems, we design an extension to the TLS protocol—Bio-TLS, which uses biometric features as an authentication factor, and selects fingerprint information as an example. It integrates with TLS to achieve seamless cross-device authentication during the handshake phase. Formal modeling and security analysis of the extended protocol are conducted using the Tamarin Prover tool to verify its security objectives. Experimental results show that the Bio-TLS protocol effectively enhances the security of client authentication, providing users with a more secure and convenient authentication method.
2) 在第n轮TLS握手中的使用:客户端存储上轮DH轮密钥对(Skrc n-1,Pkrc n-1),服务器端存储上轮客户端发送的DH轮公钥。在发送ServerHello后,服务器端生成此轮的DH轮密钥对(Skrc n,Pkrc n ),并生成此轮DH共享密钥,在扩展中发送DH轮公钥给客户端。客户端收到公钥后,生成DH共享密钥。DH棘轮算法更新密钥,生成新的棘轮密钥(Skrc n,Pkrc n ),将发送给服务器端。服务器端使用解密得到客户端更新的DH轮公钥,并存储到本地用于下轮TLS握手认证。
双方首先协商参数,其次认证服务器端的身份。服务器端生成此轮DH轮密钥对,扩展包含轮公钥。客户端收到握手消息并认证成功后,根据服务器端轮公钥,生成轮共享密钥,更新轮密钥对,。最后,使用指纹信息认证用户身份,客户端将、、和等信息作为扩展发送给服务器端。服务器端对指纹信息和共享密钥进行认证,使用轮共享密钥解密得到,更新用户信息表,将〈Fid,Did,Fppk,Pkrc n,NST〉存储在本地,并发送NST给客户端。客户端也将〈(Skrc n,Pkrc n ),NST〉存储在本地用于未来会话状态的恢复。
JAINA K, SAHOOS R, KAUBIYALJ. Online social networks security and privacy: Comprehensive review and analysis[J]. Complex & Intelligent Systems, 2021, 7(5): 2157-2177. DOI:10.1007/s40747-021-00409-7 .
[2]
RESCORLAE. The transport layer security protocol version 1.3[EB/OL]. [2018-08-30].DOI: 10.17487/rfc8446 .
[3]
VANDERSLOOTB, AMANNJ, BERNHARDM, et al. Towards a complete view of the certificate ecosystem[C]//Proceedings of the 2016 Internet Measurement Conference. New York: ACM, 2016: 543-549. DOI:10.1145/2987443.2987462 .
[4]
KHANS, LUOF, ZHANGZ J, et al. A survey on X.509 public-key infrastructure, certificate revocation, and their modern implementation on blockchain and ledger technologies[J]. IEEE Communications Surveys & Tutorials, 2023, 25(4): 2529-2568. DOI:10.1109/COMST.2023.3323640 .
[5]
WANGZ, LINJ Q, CAIQ W, et al. Blockchain-based certificate transparency and revocation transparency[C]// Financial Cryptography and Data Security. Berlin: Springer, 2019: 144-162. DOI:10.1007/978-3-662-58820-8_11 .
[6]
XIAW, WANGW, HEX, et al. Old habits die hard: A sober look at TLS client certificates in the real world[C]//2021 IEEE 20th International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom). New York: IEEE Press, 2021: 83-90. DOI:10.1109/TrustCom53373.2021.00029 .
[7]
DONGH Y, ZHANGY Z, LEEH, et al. Mutual TLS in practice: A deep dive into certificate configurations and privacy issues[C]//Proceedings of the 2024 ACM on Internet Measurement Conference. New York: ACM, 2024:214-229. DOI:10.1145/3646547.3688415 .
[8]
BOONKRONGS. Multi-factor authentication[J]. Authentication and Access Control: Practical Cryptography Methods and Tools, 2020: 133-162. DOI: 10.1007/978-1-4842-6570-3_6 .
[9]
YINZ Y, ZHOUQ, QUJ Q, et al. How far is user privacy leakage: A revisit of client certificate usage[C]//2023 8th International Conference on Cloud Computing and Big Data Analytics (ICCCBDA). New York: IEEE Press, 2023:279-284. DOI:10.1109/ICCCBDA56900.2023.10154744 .
[10]
D’ORAZIOC J, CHOOK R. A technique to circumvent SSL/TLS validations on iOS devices[J]. Future Generation Computer Systems, 2017, 74: 366-374. DOI:10.1016/j.future.2016.08.019 .
[11]
GUPTAB B, PRAJAPATIV, NEDJAHN, et al. Machine learning and smart card based two-factor authentication scheme for preserving anonymity in telecare medical information system (TMIS)[J]. Neural Computing and Applications, 2023, 35(7): 5055-5080. DOI:10.1007/s00521-021-06152-x .
[12]
KIMH. Security enhancement of biometric-based authentication systems using smart card[J]. IEEE Access, 2024, 12: 174053-174065. DOI:10.1109/ACCESS.2024.3502632 .
[13]
ALWENJ, CORETTIS, DODISY. The double ratchet: Security notions, proofs, and modularization for the signal protocol[M]//Advances in Cryptology — EUROCRYPT 2019. Cham: Springer International Publishing, 2019: 129-158. DOI:10.1007/978-3-030-17653-2_5 .
[14]
KRAWCZYKH. SIGMA: The ‘SIGn-and-MAc’ approach to authenticated diffie-Hellman and its use in the IKE protocols[M]//Advances in Cryptology — CRYPTO 2003. Berlin: Springer, 2003: 400-425. DOI:10.1007/978-3-540-45146-4_24 .
[15]
BLAKE-WILSONS, NYSTROMM, HOPWOODD, et al. Transport layer security extensions[EB/OL].[2006-04-30]. DOI: 10.17487/rfc4366 .
[16]
VAROQ, LARDIERW, YANJ. Dynamic reduced-round TLS extension for secure and energy-saving communication of IoT devices[J]. IEEE Internet of Things Journal, 2022, 9(23): 23366-23378. DOI:10.1109/JIOT.2022.3206667 .
[17]
TANGEK, HOWARDD, SHANAHANT, et al. rTLS: Lightweight TLS session resumption for constrained IoT devices[M]//Information and Communications Security. Cham: Springer International Publishing, 2020: 243-258. DOI:10.1007/978-3-030-61078-4_14 .
[18]
LEEH, SMITHZ, LIM J, et al. maTLS: How to make TLS middlebox-aware?[C]//Proceedings 2019 Network and Distributed System Security Symposium. San Diego: Internet Society, 2019:1-15. DOI:10.14722/ndss.2019.23547 .
[19]
AHN T, KWAKJ, KIMS. mdTLS: How to make middlebox-aware TLS more efficient?[M]//Information Security and Cryptology — ICISC 2023. Singapore: Springer Nature Singapore, 2024: 39-59. DOI:10.1007/978-981-97-1238-0_3 .
[20]
MEIERS, SCHMIDTB, CREMERSC, et al. The TAMARIN prover for the symbolic analysis of security protocols[M]//Computer Aided Verification. Berlin: Springer, 2013: 696-701. DOI:10.1007/978-3-642-39799-8_48 .
LIUD, WANGZ Y, LID W, et al. Formal analysis and improvement methods of 5G AKA protocol based on tamarin[J]. Journal of Cryptologic Research, 2022, 9(2): 237-247. DOI: 10.13868/j.cnki.jcr.000515(Ch ).
[23]
BASIND, SASSER, TORO-POZOJ. The EMV standard: Break, fix, verify[C]//2021 IEEE Symposium on Security and Privacy (SP). New York: IEEE Press, 2021: 1766-1781. DOI:10.1109/SP40001.2021.00037 .
[24]
SHIM, CHENJ, HEK, et al. Formal analysis and patching of {BLE-SC} pairing[C]//32nd USENIX Security Symposium. Anaheim: USENIX Association, 2023: 37-52.
[25]
LOWEG. A hierarchy of authentication specifications[C]//Proceedings 10th Computer Security Foundations Workshop. New York: IEEE Press, 1997: 31-43. DOI:10.1109/CSFW.1997.596782 .
[26]
FENGH N, GUANJ J, LIH, et al. FIDO gets verified: A formal analysis of the universal authentication framework protocol[J]. IEEE Transactions on Dependable and Secure Computing, 2023, 20(5): 4291-4310. DOI:10.1109/TDSC.2022.3217259 .
[27]
CELIS, HOYLANDJ, STEBILAD, et al. A tale of two models: Formal verification of KEMTLS via tamarin[M]//Computer Security — ESORICS 2022. Cham: Springer Nature, 2022: 63-83. DOI:10.1007/978-3-031-17143-7_4 .
[28]
SIKARWARH, DAS D. A novel MAC-based authentication scheme (NoMAS) for Internet of vehicles (IoV)[J]. IEEE Transactions on Intelligent Transportation Systems, 2023, 24(5): 4904-4916. DOI:10.1109/TITS.2023.3242291 .