使用基于时间的一次性密码的量子安全Web服务架构
Quantum-Safe Web Service Architecture Using Time-Based One-Time Passwords
浏览论文内容
中文总结 AI 辅助
本研究开发了一种量子安全Web服务架构,采用基于后量子密码学的TLS与HTTPS保障传输安全,通过HMAC驱动的TOTP保障服务安全,并实验对比了四种哈希算法的性能以支撑部署。
中文摘要 AI 辅助
一次性密码(OTP)已成为多种应用中多因素认证的常用选项,例如在网站登录流程中,OTP常与传统的基于文本的用户名和密码结合使用,以验证访问请求是否来自合法人类用户而非自动代理。然而,在涉及自动连接和系统间互操作的场景中,可能需要基于时间的一次性密码(TOTP)来建立与Web服务(WS)的安全连接。因此,本研究聚焦于探索量子安全Web服务架构的开发。所提方法通过实现基于后量子密码学(PQC)的传输层安全(TLS)和超文本传输协议安全(HTTPS)来实现传输安全管理;此外,通过构建基于密钥散列消息认证码(HMAC)的TOTP来实现Web服务安全管理。在实验环境中,本研究评估并比较了安全散列算法-2(SHA-2)、SHA-3、Ascon-Hash256和SM3的计算性能,分析了不同硬件资源条件下的所需计算时间,为未来的Web服务部署提供参考。
英文摘要
One-Time Passwords (OTPs) have become a common option for multi-factor authentication in several applications. For instance, during website login processes, OTPs are often used in conjunction with traditional text-based usernames and passwords to verify whether the access request originates from a legitimate human user rather than an automated agent. However, in scenarios involving automated connections and system-to-system interoperability, Time-Based One-Time Passwords (TOTPs) may be required to establish secure connections and access Web Services (WSs). Therefore, this study focuses on exploring the development of a quantum-safe web service architecture. The proposed approach achieves transmission security management by implementing Transport Layer Security (TLS) and HyperText Transfer Protocol Secure (HTTPS) based on Post-Quantum Cryptography (PQC). Furthermore, web service security management is realized through the construction of keyed-Hash Message Authentication Code (HMAC)-driven TOTPs. Within the experimental environment, this study evaluates and compares the computational performance of the Secure Hash Algorithm-2 (SHA-2), SHA-3, Ascon-Hash256, and SM3. The required computation time under different hardware resource conditions is analyzed for future web service deployment.