Author: 王雋凱
Chun-Kai Wang
Thesis Title: 基於近場通訊技術且適用於IPTV個人化服務之使用者身分鑑別機制
NFC-based User Authentication Mechanisms for Personalized IPTV Services
Advisor: 羅乃維
Nai-Wei Lo
Committee: 吳宗成
Tzong-Chen Wu
Kuo-Hui Yeh
Degree: 碩士
Department: 管理學院 - 資訊管理系
Department of Information Management
Thesis Publication Year: 2015
Graduation Academic Year: 103
Language: 英文
Pages: 75
Keywords (in Chinese): 主機卡模擬近場通訊身分鑑別個人化服務網路協定電視
Keywords (in other languages): NFC, Authentication, Personalized Services, IPTV, HCE
  • 網路協定電視(Internet Protocol Television,IPTV)正在成為一個平台,改變我們獲取資訊與娛樂的方式,並可提供互動功能及個人化服務(Personalized Services)。儘管IPTV服務供應商能透過機上盒(Set-top Box,STB) 獨特的硬體識別碼,執行電視觀眾識別與身分鑑別來驅動個人化服務,但此基於機上盒之認證導致整個家庭成員皆取得相同的存取權限及服務,這表明與IPTV欲提供個人化服務的目標不一致。
    隨著智慧型手機的普及且近場通訊(Near Field Communication,NFC)技術逐漸成為其標準配備,本文提出基於NFC手機之主機卡模擬(Host Card Emu-lation,HCE)技術的使用者身分鑑別機制,並設計兩套身分鑑別方案。第一個方案植基於金鑰雜湊訊息鑑別碼(Keyed-hash Message Authentication Code,HMAC),具有輕量化、低成本的優點;另一個則以數位簽章(Digital Signature)為基礎,此方案尤其適用於設計開放式服務的環境。經實驗與分析表明,本機制可滿足安全性需求並提供良好的系統易用性、可部署性及服務擴展性,適用於IPTV環境下的個人化服務,並易於部署至現有的IPTV系統。

    Internet Protocol Television (IPTV) is becoming a platform that changes the way we obtain information and entertainment, and offers interactive features and person-alized services. Although IPTV service providers can perform TV viewer identifica-tion and authentication through a unique hardware identifier of the Set-top box (STB), it is based on STB-level identification leads to whole family members get the same access level and services. This indicates that existing authentication schemes are in-consistent with IPTV's main intent of providing personalized services.
    Smartphones with NFC (Near Field Communication) capabilities have grown to become very popular over the years. The NFC-based user authentication mechanisms by using HCE (Host Card Emulation) technology, and two authentication schemes are presented in this thesis. The first is the HMAC-based authentication scheme with lightweight operations and relatively low cost. The second is the Digital Signa-ture-based authentication scheme that it particularly applies to design open IPTV ser-vices. In this thesis, the experiments and analysis show that the proposed mechanisms can meet the security requirements and provide great system usability, deployability and service scalability for personalized IPTV services. The proposed mechanisms are suitable for personalized IPTV services and able to be easily deployed onto current IPTV systems.

    中文摘要 I Abstract II 誌謝 III Contents IV List of Figures VI List of Tables VII Chapter 1 Introduction 1 Chapter 2 Related Work 4 2.1 Viewer Identification Systems for IPTV 4 2.2 Near Field Communication 8 2.2.1 Host Card Emulation 9 Chapter 3 Proposed Mechanisms 12 3.1 Overview 12 3.2 Notations 15 3.3 HMAC-based Authentication Scheme 17 3.3.1 Registration Phase 17 3.3.2 Authentication Phase 20 3.3.3 Key Update Phase 25 3.4 Digital Signature-based Authentication Scheme 28 3.4.1 Registration Phase 28 3.4.2 Authentication Phase 31 3.4.3 Key Update Phase 36 Chapter 4 Security and Performance Analysis 39 4.1 Security Analysis 39 4.1.1 Trust Boundary and Assumptions 39 4.1.2 Analysis of the proposed authentication protocols 40 4.2 Performance Analysis 43 4.2.1 Prototype Implementation 43 4.2.2 Analysis of two proposed schemes 45 Chapter 5 Discussion and Comparison 50 5.1 Usability and Deployability 50 5.2 Service Scalability 51 5.3 Comparison of the Proposed Schemes 53 5.4 Comparison with Existing Solutions 56 Chapter 6 Conclusion 59 References 60

