计算机工程与应用 ›› 2015, Vol. 51 ›› Issue (20): 72-76.

• 网络、通信、安全 • 上一篇    下一篇

基于口令的客户端/服务器认证协议

邓  飞1,朱  莹2   

  1. 1.怀化职业技术学院 信息与艺术设计系,湖南 怀化 418000
    2.北京邮电大学 网络技术研究院,北京 100876
  • 出版日期:2015-10-15 发布日期:2015-10-30

Mutual password-based client/server authentication protocol

DENG Fei1, ZHU Ying2   

  1. 1.Department of Information and Arts Design, Huaihua Vocational and Technical College, Huaihua, Hunan 418000, China
    2.Institute of Network Technology, Beijing University of Posts and Telecommunications, Beijing 100876, China
  • Online:2015-10-15 Published:2015-10-30

摘要: 身份认证是建立客户端和服务器之间安全会话的前提条件。Kim和Chung提出了一种双方的双向认证方案,其以较小的计算量得到了学者们的关注。但经分析发现,该方案并不安全:无法抵抗离线口令猜测攻击和无限次在线口令猜测攻击,也不能防止服务器伪装攻击。为了解决这些安全隐患,利用非对称Rabin密码体制提出了一种改进的方案,并基于BAN逻辑对方案的正确性进行了严格验证。最后还分析了新方案的安全性和性能。

关键词: 身份认证, Rabin体制, 口令猜测攻击, 服务器伪装攻击, BAN逻辑

Abstract: Identity authentication is the precondition for secure communication between the client and the server. Kim and Chung presented a mutual authentication scheme for client/server scene. The authors realized the mutual authentication with the lower computational cost. Based on the security analysis in this paper, it finds Kim-Chung scheme is not secure because of the off-line password guessing attack, unlimited on-line password guessing attack and server impersonation attack. To solve these security problems, it improves this protocol and discusses the security and efficiency of the novel scheme, it also proves the correctness of the protocol using BAN logic.

Key words: identity authentication, Rabin cryptosystem, password guessing attack, server impersonation attack, BAN logic