计算机工程与应用 ›› 2014, Vol. 50 ›› Issue (8): 61-65.

• 网络、通信、安全 • 上一篇    下一篇

改进的基于智能卡的远程异步认证协议

皮  兰1,2,武传坤1   

  1. 1.中国科学院 信息工程研究所 信息安全国家重点实验室,北京 100093
    2.中国科学院大学,北京 100190
  • 出版日期:2014-04-15 发布日期:2014-05-30

Improved remote asynchronous authentication scheme with smart card

PI Lan1,2, WU Chuankun1   

  1. 1.The State Key Laboratory of Information Security, Institute of Information Engineering, Chinese Academy of Sciences, Beijing 100093, China
    2.University of Chinese Academy of Sciences, Beijing 100190, China
  • Online:2014-04-15 Published:2014-05-30

摘要: 远程认证协议允许远程服务器和用户通过不安全信道实现相互认证。唐宏斌等指出Chen等方案的基于智能卡的远程认证协议存在着一些安全问题,如丢失智能卡攻击,重放攻击等,并且提出一种基于智能卡的远程认证协议,为了抵抗重放攻击而引入时间戳机制。提出一种改进的基于智能卡的远程异步认证方案,在能抵抗提到的所有攻击条件下,不需要考虑时钟同步问题而能抵抗重放攻击,使操作更简单且未增加计算性能代价。

关键词: 异步, 认证协议, 智能卡, 椭圆曲线离散对数问题

Abstract: Remote authentication scheme allows a remote server and the user to realize mutual authe-ntication through the unsafe channel. Tang Hongbin et al claim that there are some security problems in Chen et al’s scheme, such as loss of smart card attack, replay attack, etc. It proposes an improved remote authentication scheme based on smart card. But Tang Hongbin et al introduce timestamp mechanism to resist replay attack. This paper proposes a remote asynchronous authentication scheme based on smart card. The scheme doesn’t need to sonsider clock synchronization and can resist all mentioned attacks, operation is easier and the performance cost is not increased.

Key words: asynchronous, authentication scheme, smart card, Elliptic Curve Discrete Logarithm Problem(ECDLP)