Skip navigation

DSpace JSPUI

DSpace preserves and enables easy and open access to all types of digital content including text, images, moving images, mpegs and data sets

Learn More
DSpace logo
English
中文
  • Browse
    • Communities
      & Collections
    • Publication Year
    • Author
    • Title
    • Subject
    • Advisor
  • Search TDR
  • Rights Q&A
    • My Page
    • Receive email
      updates
    • Edit Profile
  1. NTU Theses and Dissertations Repository
  2. 電機資訊學院
  3. 電子工程學研究所
Please use this identifier to cite or link to this item: http://tdr.lib.ntu.edu.tw/jspui/handle/123456789/50328
Title: FIDO U2F伺服器端的實作和分析
An implementation and analysis of FIDO U2F server
Authors: Zheng-Yu Li
李政諭
Advisor: 鄭振牟
Keyword: U2F,二步驟驗證,橢圓曲線數位簽章演算法,
U2F,2-step verification,ECDSA,
Publication Year : 2016
Degree: 碩士
Abstract: 近年來,各式各樣的網路服務發展迅速,電子訊息。電子支付。網路交易。的出現,提高了使用者的方便性,卻也增加了相應的安全性隱憂,安全性多依賴於密碼的複雜程度,但密碼的複雜性卻取決於使用者的設定。因此為了增加安全性,產生了二步驟驗證的驗證方式。目前來說,二步驟驗證方式又分為 SMS簡訊傳送驗證碼,應用程式產生驗證碼,電子郵件傳送驗證碼等方式,多依賴於其他的途徑產生驗證碼後,再做確認從而達到第二步驟的驗證。有鑒於皆須仰賴其他的傳送途徑,FIDO聯盟因而提出了一種全新的驗證方式U2F,使用橢圓曲線數位簽章的驗證方式,不需要仰賴於其他傳送途徑且極其安全的二步驟驗證,本篇論文著重於伺服器端,也就是服務提供方面的實作和分析。
Many internet services grow fast in recent decades, such as e-mail, electronic payment and e-commerce. The services bring people a more convenient shopping way. However, the services also come with more security concerns. The level of the security was traditionally only decided by the complexity of a user’s password. To enhance the security, the 2-step verification was introduced. The 2-step verification is to deliver a set of the verification code to the users, and let the users to pass the code back to the server for the identity verification. The common ways for doing the 2-step verification include by SMS, by authenticator application, and by email. As all the ways listed above rely on the operation of other services, FIDO (Fast Identity Online) Alliance [1] proposed a new way called U2F (Universal Second Factor) [2] for the 2-step verification. The U2F verification was based on ECDSA (Elliptic Curve Digital Signature Algorithm) [3] and did not need a user to get the verification code from any other way. This thesis is focus on the implementation of the U2F verification from the server side and the analysis of the verification’s performance.
URI: http://tdr.lib.ntu.edu.tw/jspui/handle/123456789/50328
DOI: 10.6342/NTU201601626
Fulltext Rights: 有償授權
Appears in Collections:電子工程學研究所

Files in This Item:
File SizeFormat 
ntu-105-1.pdf
  Restricted Access
1 MBAdobe PDF
Show full item record


Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.

社群連結
聯絡資訊
10617臺北市大安區羅斯福路四段1號
No.1 Sec.4, Roosevelt Rd., Taipei, Taiwan, R.O.C. 106
Tel: (02)33662353
Email: ntuetds@ntu.edu.tw
意見箱
相關連結
館藏目錄
國內圖書館整合查詢 MetaCat
臺大學術典藏 NTU Scholars
臺大圖書館數位典藏館
本站聲明
© NTU Library All Rights Reserved