以用户为中心的双因子认证密钥协商协议  

User-centric Two-factor Authentication Key Agreement Protocol

在线阅读下载全文

作  者:杨雪 刘怡静 姜奇 王金花 李兴华 YANG Xue;LIU Yi-Jing;JIANG Qi;WANG Jin-Hua;LI Xing-Hua(School of Cyber Engineering,Xidian University,Xi’an 710119,China;Science and Technology on Communication Security Laboratory,Chengdu 610041,China)

机构地区:[1]西安电子科技大学网络与信息安全学院,陕西西安710119 [2]保密通信重点实验室,四川成都610041

出  处:《软件学报》2024年第10期4859-4875,共17页Journal of Software

基  金:国家自然科学基金(62072352,62125205,92167203,62072359);陕西省重点产业链项目(2020ZDLGY09-06)。

摘  要:当前基于用户名和口令的认证协议已难以满足日益增长的安全需求.具体而言,用户选择不同口令访问不同在线服务,极大地增加了用户记忆负担;此外,口令认证安全性低,面临许多已知攻击.为了解决此类问题,基于PS(Pointcheval-Sanders)签名提出一个以用户为中心的双因子认证密钥协商协议UC-2FAKA.首先,为防止认证因子泄露,基于PS签名构造口令和生物特征双因子凭证,并以零知识证明的方式向服务提供商(service provider,SP)验证身份;其次,采用以用户为中心的单点登录(single sign on,SSO)架构,用户可以通过向身份提供商(identity provider,IDP)注册请求身份凭证来向不同的SP登录,避免IDP和SP跟踪或链接用户;再次,采用Diffie-Hellman密钥交换认证SP身份并协商通信密钥,保证后续的通信安全;最后,对所提出协议进行全面的安全性分析和性能对比,结果表明所提出协议能够抵御各种已知攻击,且所提出协议在通信开销和计算开销上表现更优.The current authentication protocol based on username and password has been difficult to meet the increasing security requirements.Specifically,users choose different passwords to access different online services,which greatly increases the user’s memory burden.In addition,password authentication has low security and faces many known attacks.To solve such problems,this study proposes a user-centric two-factor authentication key agreement protocol UC-2FAKA based on the Pointcheval-Sanders signature.Firstly,to prevent the leakage of authentication factors,passwords,and biometric two-factor credentials are constructed based on the Pointcheval-Sanders signature.The identity is authenticated to the service provider(SP)in a zero-knowledge proof manner.Secondly,using a user-centric single sign on(SSO)architecture,users can request identity credentials by registering with an identity provider(IDP)to log in different SPs to avoid IDP or SP tracking or linking users.Thirdly,the Diffie-Hellman key exchange is used to authenticate SP identities and negotiate communication keys to ensure subsequent communication security.Finally,comprehensive security analysis and performance comparison of the proposed protocol are carried out.The results show that the proposed protocol can resist various known attacks,and the proposed protocol performs better in communication overhead and computational overhead.

关 键 词:口令 认证 凭证 双因子 

分 类 号:TP309[自动化与计算机技术—计算机系统结构]

 

参考文献:

正在载入数据...

 

二级参考文献:

正在载入数据...

 

耦合文献:

正在载入数据...

 

引证文献:

正在载入数据...

 

二级引证文献:

正在载入数据...

 

同被引文献:

正在载入数据...

 

相关期刊文献:

正在载入数据...

相关的主题
相关的作者对象
相关的机构对象