In this paper we proposed an authentication technique based on the user cards, to improve the authentication process in systems that allows remote access for the users, and raise the security rate during an exchange of their messages. in this technique the server performs two functions, the first function, register the users, and give him user ID, PIN code, and user private card contains secrecy information, which is used to encrypt user messages by using two kinds of encryption symmetric using RC4-Pr and asymmetric using RSA encryption., the second function, distribute the user's public card if the user demand that, in which the user sends the own authentication code with their own user ID and recipient user ID to the authentication check, and then the server sends the user public card to the recipient user, thus the sender user can send the messages to recipient user without back to the server again. We attained confidentiality using RC4-Pr and RSA encryption and message authentication, user signature, and mutual secret key by using RSA encryption. in this paper we also implement the proposal in [1] RC4-pr algorithm which is modified to improve the key weakness of basic RC4.
翻译:在这份文件中,我们提议了一种基于用户卡的认证技术,以改进用户远程访问系统的认证程序,并在交换信息时提高安全率。在这个技术中,服务器履行两个功能,第一个功能是,登记用户,并给他用户身份、PIN代码和用户私人卡,其中载有保密信息,用于使用RC4-Pr加密用户信息加密,使用RSA加密进行加密对称,使用RC4-Pr加密,使用RSA加密进行对称。第二个功能是,如果用户要求用户用自己的用户身份和接收人身份将自己的认证代码发送到认证检查,然后服务器将用户公共卡发送给接收人用户,因此发送人用户可以将信息发送给接收人,而无需再次返回服务器。我们通过使用RC4-Pr加密和RSA加密获得保密,用户签名和相互保密密钥认证。在本文中,我们还实施了SRSA加密的[1 RC4-4-pr算法中的建议,该算出改进了RC4的基本关键弱点。