摘要
RheeHS等人(Computer Standards & Interfaces,2009,No.1)提出的协议使用移动设备代替智能卡记忆数据降低风险和成本,但该协议仍存在一些不足。针对该问题,基于Chan-Cheng攻击案例,指出该协议难以抵抗假冒攻击和离线口令猜测攻击,为克服这些缺陷,给出一种改进方案,通过实验证明了该方案可以有效抵抗上述2种攻击,并能保证其口令的秘密性及身份认证的安全性。
Thel protocol proposed by Rhee H Set al(Computer Standards & Interfaces, 2009, No. 1) uses mobile equipment to replace smart card to reduce risk and cost, but it exists some demerits. Aiming at this problem, based on Chan-Chcng attack case, it points out that the protocol can not resist impersonation attack and off-line password guessing attack. In order to overcome these drawbacks, it gives the improved scheme. Experimental results show this scheme is strongly resistant to both of these attacks, which keeps the password secret and authenticating ID.
出处
《计算机工程》
CAS
CSCD
北大核心
2010年第7期142-143,146,共3页
Computer Engineering
基金
国家自然科学基金资助项目(10571061)
关键词
口令认证
智能卡
假冒攻击
离线口令猜测攻击
password authentication
smart card
impersonation attack
off-line password guessing attack