北京航空航天大学学报 ›› 2005, Vol. 31 ›› Issue (10): 1076-1079.

• 论文 • 上一篇    下一篇

一种远程身份认证方案的分析与改进

张利华, 吕善伟   

  1. 北京航空航天大学 电子信息工程学院, 北京 100083
  • 收稿日期:2004-06-09 出版日期:2005-10-31 发布日期:2010-09-20
  • 作者简介:张利华(1972-),男,湖北京山人,博士生, hbzlh@163.com.

Analysis and improvements of a remote authentication scheme

Zhang Lihua, Lü Shanwei   

  1. School of Electronics and Information Engineering, Beijing University of Aeronautics and Astronautics, Beijing 100083, China
  • Received:2004-06-09 Online:2005-10-31 Published:2010-09-20

摘要: 口令认证是远程身份认证中实用的方法.分析了一个给出的使用智能卡的口令认证方案的安全性,指出该方案是不安全的:不能抵御并行会话攻击,攻击者可以利用截获的信息生成合法的登陆信息假冒合法用户登陆,并通过认证获得授权,而不需要知道用户口令;不能抵御更改时戳攻击,攻击者可以更改截获信息的时戳,假冒合法用户登陆远程主机或假冒合法远程主机.同时,引入登陆计数器,采用一卡一密,给出了一种改进的使用智能卡的口令认证方案.该方案允许用户自主选择并更改口令,实现了双向认证;能够抵御重放攻击、内部攻击,具备强安全修复性;能够抵御并行会话攻击和更改时戳攻击,具有更好的安全性.

Abstract: Password authentication scheme is a very promising and practical solution to remote user authentication.The security of a proposed password authentication scheme using smart cards is analyzed. The scheme has some weaknesses: it cannot resist parallel session attack, an intruder without knowing users' password can masquerade as a legal user by creating a valid login message from the eavesdropped communication, then passes the authentication phase and gains the authority of the legitimate user; it is also vulnerable to changing timestamps attack, an intruder can masquerade as a legal user or impersonate a valid authentication system by changing timestamps of the messages from eavesdropped communication. Furthermore, an enhanced password authentication scheme using smart cards with better security strength by using login counter and different keys via cards is proposed. The scheme has many merits as following: it lets users freely choose and change their passwords at their own will; it provides mutual authentication between two entities; it resists message replaying attack and insider attack; it has strong security reparability by using extended identities and smart cards; it also withstands parallel session attack and changing timestamps attack.

中图分类号: 


版权所有 © 《北京航空航天大学学报》编辑部
通讯地址:北京市海淀区学院路37号 北京航空航天大学学报编辑部 邮编:100191 E-mail:jbuaa@buaa.edu.cn
本系统由北京玛格泰克科技发展有限公司设计开发