http://hdl.handle.net/10119/9505

タイトル: Practical and Secure Recovery of Disk Encryption Key Using Smart Cards
著者: OMOTE, Kazumasa
KATO, Kazuhiko
キーワード: user authentication
key recovery
smart card
発行日: 2010-05-01
出版者: 電子情報通信学会
誌名: IEICE TRANSACTIONS on Information and Systems
巻: E93-D
号: 5
開始ページ: 1080
終了ページ: 1086
DOI: 10.1587/transinf.E93.D.1080
抄録: In key-recovery methods using smart cards, a user can recover the disk encryption key in cooperation with the system administrator, even if the user has lost the smart card including the disk encryption key. However, the disk encryption key is known to the system administrator in advance in most key-recovery methods. Hence user's disk data may be read by the system administrator. Furthermore, if the disk encryption key is not known to the system administrator in advance, it is difficult to achieve a key authentication. In this paper, we propose a scheme which enables to recover the disk encryption key when the user's smart card is lost. In our scheme, the disk encryption key is not preserved anywhere and then the system administrator cannot know the key before key-recovery phase. Only someone who has a user's smart card and knows the user's password can decrypt that user's disk data. Furthermore, we measured the processing time required for user authentication in an experimental environment using a virtual machine monitor. As a result, we found that this processing time is short enough to be practical.
Rights: Copyright (C)2010 IEICE. Kazumasa OMOTE, Kazuhiko KATO, IEICE TRANSACTIONS on Information and Systems, E93-D(5), 2010, 1080-1086. http://www.ieice.org/jpn/trans_online/
URI: http://hdl.handle.net/10119/9505
