一个新的智能卡远程用户认证方案  被引量:3

A new remote user authentication scheme of using smart card

在线阅读下载全文

作  者:沈忠华[1] 于秀源[1] 

机构地区:[1]杭州师范大学理学院,浙江杭州310036

出  处:《浙江大学学报(理学版)》2008年第2期145-149,共5页Journal of Zhejiang University(Science Edition)

基  金:国家自然科学基金资助项目(10671051,10271037);浙江省自然科学基金资助项目(103060);浙江省教育厅科研计划项目(20061069);杭州师范大学科研项目(2006XNZ03)

摘  要:LAMPORT第一次提出了一个带有智能卡的远程用户认证方案,随后HWANG和LI指出了该方案存在的问题,并提出了一个新的方案.然而HWANG-LI方案中仍有不少安全漏洞,CHAN-CHANG、SHEN-LIN-HWANG和CHANG-HWANG先后对该方案进行了不同方式的攻击,并提出了一系列改进方案.最近KUMAR和AWASTIHI-LAL又分别提出了两个新的方案.然而,这些方案都存在一个共同的弱点,那就是由系统中心掌握用户的口令,这给用户带来了安全隐患.为了解决这个问题,文章在这些方案的模式下,利用二元一次不定方程解的不定性和离散对数问题的难解性,提出了一个新的远程用户认证方案.该方案主要在注册阶段和登录阶段加强了安全性,不仅可以抵御以往类似CHAN-CHENG和CHANG-HWANG的攻击,而且口令由用户掌握,并可随时更改,保证了用户的安全.LAMPORT proposed the first well-known remote password authentication scheme of using smart cards. HWANG and LI pointed out some problems in the LAMPORT's scheme and they proposed a new remote user authentication scheme. Unfortunately, HWANG and LI's scheme has some weaknesses in security. CHAN-CHANG, SHEN-LIN-HWANG and then CHANG-HWANG had some attacks on HWANG-LI's scheme and some modified schemes were proposed. Recently KUMAR and AWASTIHI-LAL also introduced two remote user authentication schemes. But these schemes all have a weakness in common: the AS and the remote user share a secret which is called password. Actually, this property is a disadvantage for the security. By using bivariate simple equation and the discrete logarithm problem, a new remote user authentication scheme is presented to solve this problem. The scheme can withstand the attack that is similar to CHAN and CHENG'attack and CHANG and HWANG' attack in registration phase and authentication phase. The password is controlled by the user, and can be changed at any time.

关 键 词:认证方案 远程用户 智能卡 密码分析 安全 

分 类 号:TP309[自动化与计算机技术—计算机系统结构] O153[自动化与计算机技术—计算机科学与技术]

 

参考文献:

正在载入数据...

 

二级参考文献:

正在载入数据...

 

耦合文献:

正在载入数据...

 

引证文献:

正在载入数据...

 

二级引证文献:

正在载入数据...

 

同被引文献:

正在载入数据...

 

相关期刊文献:

正在载入数据...

相关的主题
相关的作者对象
相关的机构对象