Keyword Search:


Bookmark and Share

Extending TLS with mutual attestation for platform integrity assurance

Abdul Aziz, Nor Azah and Udzir, Nur Izura and Mahmod, Ramlan (2014) Extending TLS with mutual attestation for platform integrity assurance. Journal of Communications, 9 (1). pp. 63-72. ISSN 2374-4367; ESSN: 1796-2021

[img] PDF (Abstract)
35Kb

Official URL: http://www.jocm.us/index.php?m=content&c=index&a=s...

Abstract

Normally, secure communication between client-server applications is established using secure channel technologies such as Transport Layer Security (TLS). TLS is cryptographic protocol which ensures secure transmission of data and authenticity of communication at each endpoint platform. However, the protocol does not provide any trustworthiness assurance of the involved endpoint. This paper incorporates remote attestation in the TLS key exchange protocol to solve this issue.The proposed embedded attestation extension in TLS protocol will provide assurance of sender's platforms integrity to receiver, and vice versa.The CA responsibility in TLS is replaced using own Trusted Certificate Authority (TCA) in our protocol. The credibility of the proposed protocol is studied to secure against replay attack and collusion attack. The proof is performed using AVISPA with High Level Protocol Specification (HLPSL) through Dolev-Yao intruder model implementation of the proposed protocol.

Item Type:Article
Keyword:Certificate Authority (CA); Integrity; Remote attestation; SSL/TLS extension; TPM
Faculty or Institute:Faculty of Computer Science and Information Technology
Publisher:Engineering and Technology Publishing
DOI Number:10.12720/jcm.9.1.63-72
Altmetrics:http://www.altmetric.com/details.php?domain=psasir.upm.edu.my&doi=10.12720/jcm.9.1.63-72
ID Code:37590
Deposited By: Nabilah Mustapa
Deposited On:18 Dec 2015 09:51
Last Modified:18 Dec 2015 09:51

Repository Staff Only: Edit item detail

Document Download Statistics

This item has been downloaded for since 18 Dec 2015 09:51.

View statistics for "Extending TLS with mutual attestation for platform integrity assurance"