摘要
在远程认证中,主要采用的仍然是基于口令的认证方案。为了满足安全性的需求,许多基于智能卡的远程用户认证方案被提出,但是绝大多数的方案不支持用户对口令的自由选取和更改,且许多方案中需要存储核对表。提出了一种新型的双向认证方案并且分析了其安全特性。所述方案支持用户自由更改口令且无需表格,可以防止ID窃取、猜测攻击、中间人攻击、拒绝服务攻击等。
Password-based authentication schemes are the most widely used techniques for remote user authentication. To fulfill more security, many smart cards-based remote user authentication schemes have been proposed. Most of the schemes do not allow the users to choose and change their passwords, and maintain a verifier table to verify the validity of the user login. In this paper we present a new mutual authentication scheme using smart card and give the security properties. Our scheme allows the users to choose and change their passwords freely, and do not maintain any verifier table. The scheme is secure against ID- theft, and can resist guessing attacks, insider attacks , the reply attacks.
出处
《黑龙江水专学报》
2005年第4期146-147,共2页
Journal of Heilongjiang Hydraulic Engineering College
基金
山东省科技攻关项目(003090309)
关键词
安全
双向认证
智能卡
security
mutual authentication
smart card