摘要
PKI技术已广泛地应用于信息安全领域,在Linux系统中的应用也有着实际而且深远的意义。本文分析了Linux的基于用户名和口令的认证方式及其存在的安全隐患,提出了一种基于PKI及盘问/响应的用户认证方式,可有效地防止重放攻击及字典攻击,为PKI在Linux操作系统安全中的进一步研究提供了一个极好的范例。
The PKI technology has been widely used in information security domain. Its applica-tion in Linux system is far-reaching. This paper analyzes the authentication theory based onusername and password and the security trouble in Linux system. A new authentication mode foruser based on PKI and challenge/response is produced. It can prevent replay attack and dictio-nary attack. It produces a good example for further security study in Linux operating system.
出处
《网络安全技术与应用》
2004年第5期44-45,共2页
Network Security Technology & Application