During the past decade,rapid advances in wireless communication technologies have made it possible for users to access desired services using hand-held devices.Service providers have hosted multiple servers to ensure ...During the past decade,rapid advances in wireless communication technologies have made it possible for users to access desired services using hand-held devices.Service providers have hosted multiple servers to ensure seamless online services to end-users.To ensure the security of this online communication,researchers have proposed several multi-server authentication schemes incorporating various cryptographic primitives.Due to the low power and computational capacities of mobile devices,the hash-based multi-server authenticated key agreement schemes with offline Registration Server(RS)are the most efficient choice.Recently,Kumar-Om presented such a scheme and proved its security against all renowned attacks.However,we find that their scheme bears an incorrect login phase,and is unsafe to the trace attack,the Session-Specific Temporary Information Attack(SSTIA),and the Key Compromise Impersonation Attack(KCIA).In fact,all of the existing multi-server authentication schemes(hash-based with offline RS)do not withstand KCLA.To deal with this situation,we propose an improved hash-based multi-server authentication scheme(with offline RS).We analyze the security of the proposed scheme under the random oracle model and use the t4Automated Validation of Internet Security Protocols and Applications''(AVISPA)tool.The comparative analysis of communication overhead and computational complexity metrics shows the efficiency of the proposed scheme.展开更多
Build a general software development platform for industrial process supervisor and management system by combining the technology of industrial configuration and Client/Server model, and introduce the architecture and...Build a general software development platform for industrial process supervisor and management system by combining the technology of industrial configuration and Client/Server model, and introduce the architecture and topological application of this platform. It puts forward a solution to the real time problem in the industrial distributed supervisor system.展开更多
Most of the password based authentication protocols make use of the single authentication server for user's authentication. User's verifier information stored on the single server is a main point of susceptibi...Most of the password based authentication protocols make use of the single authentication server for user's authentication. User's verifier information stored on the single server is a main point of susceptibility and remains an attractive target for the attacker. On the other hand, multi-server architecture based authentication protocols make it difficult for the attacker to find out any significant authentication information related to the legitimate users. In 2009, Liao and Wang proposed a dynamic identity based remote user authentication protocol for multi-server environment. However, we found that Liao and Wang's protocol is susceptible to malicious server attack and malicious user attack. This paper presents a novel dynamic identity based authentication protocol for multi-server architecture using smart cards that resolves the aforementioned flaws, while keeping the merits of Liao and Wang's protocol. It uses two-server paradigm by imposing different levels of trust upon the two servers and the user's verifier information is distributed between these two servers known as the service provider server and the control server. The proposed protocol is practical and computational efficient because only nonce, one-way hash function and XOR operations are used in its implementation. It provides a secure method to change the user's password without the server's help. In e-commerce, the number of servers providing the services to the user is usually more than one and hence secure authentication protocols for multi-server environment are required.展开更多
In order to design a new kind of mobile database management system (DBMS)more suitable for mobile computing than the existent DBMS, the essence of database systems in mobilecomputing is analyzed. An opinion is introdu...In order to design a new kind of mobile database management system (DBMS)more suitable for mobile computing than the existent DBMS, the essence of database systems in mobilecomputing is analyzed. An opinion is introduced that the mobile database is a kind of dynamicdistributed database, and the concept of virtual servers to translate the clients' mobility to theservers' mobility is proposed. Based on these opinions, a kind of architecture of mobile DBMS, whichis of versatility, is presented. The architecture is composed of a virtual server and a local DBMS,the virtual server is the kernel of the architecture and its functions are described. Eventually,the server kernel of a mobile DBMS prototype is illustrated.展开更多
由于油气勘探开发中井下高温高压和复杂压力系统导致钻井过程面临的风险日益增大,因此迫切需要一款集工况数据模拟计算与井下复杂监测控制相结合的软件系统,助力实现安全高效钻井。为此,运用先进的控压钻井技术,实时监测井底压力、钻井...由于油气勘探开发中井下高温高压和复杂压力系统导致钻井过程面临的风险日益增大,因此迫切需要一款集工况数据模拟计算与井下复杂监测控制相结合的软件系统,助力实现安全高效钻井。为此,运用先进的控压钻井技术,实时监测井底压力、钻井液循环出入口流量差和密度等关键参数的变化,分析井下工况的变化,实现在钻井过程中井筒压力的快速、准确控制,有效降低钻井过程的安全隐患,及早发现并快速控制井下复杂情况,为形成预测、预控和快速处置的井筒安全提供支持。设计的控压钻井计算模拟与控制软件旨在从录井、PWD(Pressure While Drilling)、MWD(Measure While Drilling)、控压等设备获取钻井相关信息,建立水力学模型计算井筒压力、流量等参数。通过采用客户端/服务端网络架构,实现了多个客户端同时连接一个服务端,达到客户端数据同步的效果,经现场验证既可满足单机使用,又可方便网络连接,实现后方集中分析处理与远程操控。结果表明,该软件能准确地模拟计算各种钻井参数,保证安全高效钻井。实现了控压钻井由现场工程师处理模式转变为后方基于数据平台的模式,奠定了1个平台对N个现场控压钻井装备之间的互联互通基础,有力推动了控压钻井的智能化发展。展开更多
文摘During the past decade,rapid advances in wireless communication technologies have made it possible for users to access desired services using hand-held devices.Service providers have hosted multiple servers to ensure seamless online services to end-users.To ensure the security of this online communication,researchers have proposed several multi-server authentication schemes incorporating various cryptographic primitives.Due to the low power and computational capacities of mobile devices,the hash-based multi-server authenticated key agreement schemes with offline Registration Server(RS)are the most efficient choice.Recently,Kumar-Om presented such a scheme and proved its security against all renowned attacks.However,we find that their scheme bears an incorrect login phase,and is unsafe to the trace attack,the Session-Specific Temporary Information Attack(SSTIA),and the Key Compromise Impersonation Attack(KCIA).In fact,all of the existing multi-server authentication schemes(hash-based with offline RS)do not withstand KCLA.To deal with this situation,we propose an improved hash-based multi-server authentication scheme(with offline RS).We analyze the security of the proposed scheme under the random oracle model and use the t4Automated Validation of Internet Security Protocols and Applications''(AVISPA)tool.The comparative analysis of communication overhead and computational complexity metrics shows the efficiency of the proposed scheme.
基金The Natural Science Foundation of Hunan Province!(No.96 10 1 3 0 )
文摘Build a general software development platform for industrial process supervisor and management system by combining the technology of industrial configuration and Client/Server model, and introduce the architecture and topological application of this platform. It puts forward a solution to the real time problem in the industrial distributed supervisor system.
文摘Most of the password based authentication protocols make use of the single authentication server for user's authentication. User's verifier information stored on the single server is a main point of susceptibility and remains an attractive target for the attacker. On the other hand, multi-server architecture based authentication protocols make it difficult for the attacker to find out any significant authentication information related to the legitimate users. In 2009, Liao and Wang proposed a dynamic identity based remote user authentication protocol for multi-server environment. However, we found that Liao and Wang's protocol is susceptible to malicious server attack and malicious user attack. This paper presents a novel dynamic identity based authentication protocol for multi-server architecture using smart cards that resolves the aforementioned flaws, while keeping the merits of Liao and Wang's protocol. It uses two-server paradigm by imposing different levels of trust upon the two servers and the user's verifier information is distributed between these two servers known as the service provider server and the control server. The proposed protocol is practical and computational efficient because only nonce, one-way hash function and XOR operations are used in its implementation. It provides a secure method to change the user's password without the server's help. In e-commerce, the number of servers providing the services to the user is usually more than one and hence secure authentication protocols for multi-server environment are required.
文摘In order to design a new kind of mobile database management system (DBMS)more suitable for mobile computing than the existent DBMS, the essence of database systems in mobilecomputing is analyzed. An opinion is introduced that the mobile database is a kind of dynamicdistributed database, and the concept of virtual servers to translate the clients' mobility to theservers' mobility is proposed. Based on these opinions, a kind of architecture of mobile DBMS, whichis of versatility, is presented. The architecture is composed of a virtual server and a local DBMS,the virtual server is the kernel of the architecture and its functions are described. Eventually,the server kernel of a mobile DBMS prototype is illustrated.
文摘由于油气勘探开发中井下高温高压和复杂压力系统导致钻井过程面临的风险日益增大,因此迫切需要一款集工况数据模拟计算与井下复杂监测控制相结合的软件系统,助力实现安全高效钻井。为此,运用先进的控压钻井技术,实时监测井底压力、钻井液循环出入口流量差和密度等关键参数的变化,分析井下工况的变化,实现在钻井过程中井筒压力的快速、准确控制,有效降低钻井过程的安全隐患,及早发现并快速控制井下复杂情况,为形成预测、预控和快速处置的井筒安全提供支持。设计的控压钻井计算模拟与控制软件旨在从录井、PWD(Pressure While Drilling)、MWD(Measure While Drilling)、控压等设备获取钻井相关信息,建立水力学模型计算井筒压力、流量等参数。通过采用客户端/服务端网络架构,实现了多个客户端同时连接一个服务端,达到客户端数据同步的效果,经现场验证既可满足单机使用,又可方便网络连接,实现后方集中分析处理与远程操控。结果表明,该软件能准确地模拟计算各种钻井参数,保证安全高效钻井。实现了控压钻井由现场工程师处理模式转变为后方基于数据平台的模式,奠定了1个平台对N个现场控压钻井装备之间的互联互通基础,有力推动了控压钻井的智能化发展。