计算机工程与应用 ›› 2010, Vol. 46 ›› Issue (30): 108-111.DOI: 10.3778/j.issn.1002-8331.2010.30.032

• 网络、通信、安全 • 上一篇    下一篇

基于生物特征和口令放大的远程认证协议

杨得新1,2,杨 波1,郭艾侠1   

  1. 1.华南农业大学 信息学院,广州 510630
    2.广东白云学院 计算机系 广州 510430
  • 收稿日期:2009-03-11 修回日期:2009-04-28 出版日期:2010-10-21 发布日期:2010-10-21
  • 通讯作者: 杨得新

Remote authentication protocol based on biometrics and password amplification

YANG De-xin1,2,YANG Bo1,GUO Ai-xia1   

  1. 1.College of Information,South China Agricultural University,Guangzhou 510630,China
    2.Department of Computer,Guangdong Baiyun Institute,Guangzhou 510430,China
  • Received:2009-03-11 Revised:2009-04-28 Online:2010-10-21 Published:2010-10-21
  • Contact: YANG De-xin

摘要: 基于口令的认证协议具有简单、方便、强适应性及移动性等优点,它广泛应用于网上银行、ATM等远程登录环境中。但是一般用户的口令具有低熵、安全性低、口令数据难以保护等缺点,从而使系统存在许多安全隐患。口令放大是这样的一种算法,它输入用户的低熵的口令和一个高熵的随机数,然后输出一个高熵的新口令,从而提高了系统的安全性,也不增加用户的负担。人体生物特征是人体所固有的生理和行为特征,而模糊提取器可以从人体的生物特征中提取出高熵的随机串。生物特征和口令放大的结合,恰好可以克服基于口令的认证协议的缺点,提高其安全性。提出了一种结合人体生物特征和口令放大的单向认证协议,充分发挥了基于口令的认证协议所具有的简单易用和生物特征高熵、安全性高等优点,并且具有一定的容错能力。

关键词: 认证协议, 生物特征, 口令放大, 模糊提取器

Abstract: The password-based authentication has advantages of simplicity,convenience,flexibility and mobility.It is widely used in Internet banking,ATM,such as remote login environment,ATM etc.The intrinsic problems with password-based authentication are password itself has lower entropy,lower security and the password file is very hard to protect.The password amplification is such an algorithm,which accepts a lower entropy password and a higher entropy random number and outputs a new higher entropy password,this can improve the security of authentication protocol and do not increase the hardness of users.Human biometric is the owned physiological and behavioral characteristics,the fuzzy extractor can extract a high entropy random string from the human biometrics.The combination of password amplification and biometrics can overcome the drawbacks of password-based authentication protocol,and enhance its security.In this paper,a new one-way?authentication protocol,which integrates the human biometric and password amplification,is proposed,it has the advantages of human biometric and password authentication and has ability of error-tolerant.

Key words: authentication protocol, human biometrics, password amplification, fuzzy extractor

中图分类号: