• Journal of Internet Computing and Services
    ISSN 2287 - 1136 (Online) / ISSN 1598 - 0170 (Print)
    https://jics.or.kr/

Study on Elliptic Curve Diffie-Hellman based Verification Token Authentication Implementation


Cheong H. Choi, Journal of Internet Computing and Services, Vol. 19, No. 5, pp. 55-66, Oct. 2018
10.7472/jksii.2018.19.5.55, Full Text:
Keywords: authentication, Diffie-Hellman, Elliptic Curve Crypto

Abstract

Since existing server-based authentications use vulnerable password-based authentication, illegal leak of personal data occurs frequently. Since this can cause illegal ID compromise, alternative authentications have been studied. Recently token-based authentications like OAuth 2.0 or JWT have been used in web sites, however, they have a weakness that if a hacker steals JWT token in the middle, they can obtain plain authentication data from the token, So we suggest a new authentication method using the verification token of authentic code to encrypt authentication data with effective time. The verification is to compare an authentication code from decryption of the verification-token with its own code. Its crypto-method is based on do XOR with ECDH session key, which is so fast and efficient without overhead of key agreement. Our method is outstanding in preventing the personal data leakage.


Statistics
Show / Hide Statistics

Statistics (Cumulative Counts from November 1st, 2017)
Multiple requests among the same browser session are counted as one view.
If you mouse over a chart, the values of data points will be shown.


Cite this article
[APA Style]
Choi, C. (2018). Study on Elliptic Curve Diffie-Hellman based Verification Token Authentication Implementation. Journal of Internet Computing and Services, 19(5), 55-66. DOI: 10.7472/jksii.2018.19.5.55.

[IEEE Style]
C. H. Choi, "Study on Elliptic Curve Diffie-Hellman based Verification Token Authentication Implementation," Journal of Internet Computing and Services, vol. 19, no. 5, pp. 55-66, 2018. DOI: 10.7472/jksii.2018.19.5.55.

[ACM Style]
Cheong H. Choi. 2018. Study on Elliptic Curve Diffie-Hellman based Verification Token Authentication Implementation. Journal of Internet Computing and Services, 19, 5, (2018), 55-66. DOI: 10.7472/jksii.2018.19.5.55.