摘要
利用IC(integrated circuit)卡、RSA密码体制以及离散对数,设计了一种适用于移动计算环境的口令认证协议。在服务器侧无需保存验证表,增强了系统的安全性。为了适应移动计算环境中终端计算能力较弱以及无线带宽相对较窄的特点,该协议在无线信道上只需一次认证消息交互。并且,用户在修改密码的时候无需网络侧服务器的参与,在本地终端即可独立完成。利用M/G/1/N排队模型分析协议性能并与TLS(transport layer security)协议比较。
By means of IC (integrated circuit) card, RSA cryptography, and discrete logarithm, a password authentication scheme for mobile computing environment was presented. No verification tables were preserved at the server side to consolidate the security. To be applicable for the mobile computing environment, the scheme was designed as a one-roundtrip protocol to meet the computation-constraint terminals and narrow-bandwidth radio interface. Moreover, the passwords in use could be changed by users without any interaction with servers over the radio. The performance of the scheme was measured by making use of M/G/1/N queuing model and compared with that of TLS.
出处
《通信学报》
EI
CSCD
北大核心
2007年第5期36-42,共7页
Journal on Communications
基金
国家杰出青年科学基金资助项目(60525110)
新世纪优秀人才支持计划(NCET-04-0111)
高等学校博士学科点专项科研基金资助项目(20030013006)~~
关键词
认证
密钥建立
口令
排队论
性能分析
TLS
RSA
authentication
key establishment
password
queuing model
performance analysis
TLS
RSA