Title :
Combining RFID-based physical access control systems with digital signature systems to increase their security
Author :
Larchikov, Andrey ; Panasenko, Sergey ; Pimenov, Alexander V. ; Timofeev, Petr
Author_Institution :
ANCUD Ltd., Moscow, Russia
Abstract :
Digital signature systems are adopted worldwide. Using the legally valid digital signatures for payment orders demands involving the strong security mechanisms to prevent secret keys leakage or unauthorized use and other possible risks. Typically digital signature calculation is performed by cryptographic smart cards or USB tokens containing secrets keys. Personal computers with digital signature systems are usually equipped with access control and management systems that allow to provide restricted access to the computers and to supervise processes running on them. However, it keeps some possibilities of attacks on digital signature systems, mainly resulting from incorrect or erroneous user behavior. We propose to use RFID technology to combine functions of physical access control, computer´s access control and management, and digital signature systems. This combination allows to drastically increase systems´ security. Even low-end RFID tags can add one security level into the system, but high-end RFID tags with cryptographic possibilities and slight modification of digital signature calculation procedure make it possible to prevent obtaining digital signatures for fraudulent documents. The further evolution of the proposed scheme is permanent monitoring by means of periodical controlling user´s RFID tag, whether authenticated user is present at the computer with restricted access.
Keywords :
access control; authorisation; digital signatures; private key cryptography; radiofrequency identification; smart cards; RFID tag; USB token; attack possibility; computer access control; cryptographic possibility; cryptographic smart card; digital signature system; fraudulent document; personal computer; physical access control system; radiofrequency identification; restricted access; secret key leakage; security mechanism; user authentication; Access control; Cryptography; Digital signatures; RFID tags; Smart cards; RFID; access control; digital signature; smart cards;
Conference_Titel :
Software, Telecommunications and Computer Networks (SoftCOM), 2014 22nd International Conference on
Conference_Location :
Split
DOI :
10.1109/SOFTCOM.2014.7039085