基于随机数和Hash函数的认证方案  被引量:7

Nonce and Hash Based Authentication Scheme

在线阅读下载全文

作  者:张利华[1] 

机构地区:[1]北京航空航天大学

出  处:《微电子学与计算机》2007年第6期80-83,共4页Microelectronics & Computer

基  金:国家自然科学基金项目(60271012)

摘  要:分析了一个低开销的基于随机数的远程身份认证方案的安全性,指出了该方案的安全缺陷。构造了一个基于随机数和Hash函数、使用智能卡的远程身份认证方案(NHRA方案)。该方案使用随机数,避免了使用时戳带来的重放攻击的潜在风险。该方案允许用户自主选择和更改口令,实现了双向认证,有更小的计算开销;能够抵御假冒远程主机攻击、抵御假冒合法用户攻击;能够迅速检测口令输入错误及正确判断认证失败原因;具备强安全修复性。The security of a new proposed remote user authentication scheme is analyzed. Whereby it uses nonce ran- dom and has very low computational costs. However, this scheme still has many secure faults. The weakness of the scheme is demonstrated. NHRA, a novel nonce and Hash based remote user authentication scheme using smart cards is also presented. In order to avoid the risk of message replay attack, the scheme uses nonce random instead of using time stamps. NHRA has many merits: it let users freely choose and change password at their own will; it provides mutual authentication between two entities; it has more lower computational costs; it resists masquerading remote system or legitimate user attack; in addition, it can detect fast when user inputs wrong password and give the correct indication of the reason; Furthermore, it has strong security reparability.

关 键 词:身份认证 口令 随机数 智能卡 安全分析 

分 类 号:TP393.08[自动化与计算机技术—计算机应用技术]

 

参考文献:

正在载入数据...

 

二级参考文献:

正在载入数据...

 

耦合文献:

正在载入数据...

 

引证文献:

正在载入数据...

 

二级引证文献:

正在载入数据...

 

同被引文献:

正在载入数据...

 

相关期刊文献:

正在载入数据...

相关的主题
相关的作者对象
相关的机构对象