检索规则说明:AND代表“并且”;OR代表“或者”;NOT代表“不包含”;(注意必须大写,运算符两边需空一格)
检 索 范 例 :范例一: (K=图书馆学 OR K=情报学) AND A=范并思 范例二:J=计算机应用与软件 AND (U=C++ OR U=Basic) NOT M=Visual
出 处:《信息安全与通信保密》2013年第7期69-71,共3页Information Security and Communications Privacy
摘 要:近几年,NFC在移动市场发展迅猛,尤其在移动支付领域表现突出,这使得其成为黑客、各大运营商及第三方支付平台关注的焦点,因此它的安全问题也被推到了风口浪尖。针对威胁性较高的中间人攻击和重放攻击提出了一种可证安全的身份验证方案,通过引入带外验证保证注册阶段的安全性,同时通过两次生成的随机数组不会完全一样的特性,让两台设备同时参与认证,保证身份验证阶段的安全性。实验结果表明,该方案能有效地防止中间人攻击和重放攻击,具有较高的安全性。In recent years, the NFC develops rapidly in the mobile market, particularly in the field of mobile payments, and this makes it the focus of hackers, major carriers and third-party payment platform. Thus its security issue is pushed to the prominent position. This paper proposes a security-verifiable ID authentication scheme for preventing the man- in-the-middle attack and replay attack. And the security of registration phrase is guaranteed by introducing out-of- band authentication. Based on the completely different characteristics of random number groups generated twice, the two devices are made to participate in the certification, thus to ensure the security of the authentication phase. The experiment indicates that this scheme could effectively prevent the man-in-the-middle attack.
关 键 词:近场通讯 中间人攻击 身份认证 椭圆曲线密码体制
分 类 号:TP393.08[自动化与计算机技术—计算机应用技术]
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在链接到云南高校图书馆文献保障联盟下载...
云南高校图书馆联盟文献共享服务平台 版权所有©
您的IP:216.73.216.171