节点文献
通信安全认证与保密协议相关问题研究
Investigation on the Related Problems in Secure Authentication and Protocols for Communication Systems
【作者】 袁丁;
【导师】 范平志;
【作者基本信息】 西南交通大学 , 交通信息工程及控制, 2002, 博士
【摘要】 通信网络面临多种多样的安全威胁,如何有效地保护重要数据信息、提高通信网络的安全性已经成为一个日益重要的迫切任务。为此,本论文深入研究了基于密码技术的几个关键认证问题,即身份认证技术、群数字签名、电子证据与反拒认机制等,同时也研究了多用户通信协议的安全问题。 首先,论文分析了一种基于远程系统的远程口令身份认证方案SAS的安全性,指出了其中的安全漏洞。提出了一种新的基于口令的身份识别方案SEPA,与现有的方法比较,综合性能得到较大提高。具体表现为:支持“弱口令”,即用户可以使用长度较短的口令;为了减少计算负荷,在用户端和服务器端均不使用对称或非对称密码加密算法;可以抵御字典攻击,重传攻击和服务器拒绝服务攻击。接着,本文提出了一种基于用户智能卡的离散对数和ElGamal公钥体制远程身份识别方案。该方案有以下特点:在注册阶段,合法用户可以自由地选择自己的口令;在口令验证阶段,用户与服务器之间只须进行一次通信,且服务器端无须存放用户的口令验证表;使用时戳来抵御重传攻击,并克服了Hwang-Li方案存在的伪造攻击的弱点。 其次,指出了Ao-Chen-Bai群签名方案的安全隐患,即攻击者可以构造一个合法的群签名,从而可以对系统实施伪造攻击。类似地,Tseng-JanⅡ方案也存在类似的攻击。本文基于Tseng方案,提出了一种改进的群签名方案。本方案既可以抵御伪造攻击,又满足不可链接性的特点,可以克服Ao-Chen-Bai群签名和Tseng-JanⅡ群签名方案存在的不足。 为了保证网络上传输数据的机密性、完整性、公正性和有效性,本文基于可信的第三方提出了一个面向传输的电子证据与反拒认协议TEENP。分析了已存在的基于可信的第三方的电子证据与反拒认协议FNP以及CMP的优劣。论文比较了TEENP与CMP协议的各项性能指标,扩充了类BAN逻辑的语义和逻辑推理规则,并使用类BAN逻辑证明了TEENP的可追究性。与相关协议相比,本协议在安全性、计算负荷和通信负荷方面均有很大提高。 接着,通过对多用户间密钥协商协议GDH.2进行深入分析,指出了其中的安全漏洞,然后在其基础上,提出了一个改进的M-GDH.2协议。相对于GDH.2而言,M-GDH.2只以增加很小的计算和通信负荷为代价,安全性能得到了较大 西南交通大学博士研究生学位论文 第*页的提高,系统满足“前向安全性”,可以抵御“ Denning习acco”攻击和重传攻击。并讨论了通信时用户动态增减变化情况。以协议M-GDH.2为基础,论文还设计了一个三用户即时多用户保密通信示范系统,该系统允许用户间自由协商会话密钥,并使用会话密钥进行保密通信。
【Abstract】 Network is faced with various security threats, and it is important to effectively protect crucial data and to improve the security of computer networks. Therefore, this thesis aims at several key authentication techniques based on cipher technique in great detail, including identity authentication technique, group signature technique, electronic evidence and nonrepudiation mechanism. Besides, a secure communication scheme among multiusers is investigated and discussed particularly.First of all, the security of SAS ( Simple and Secure Password Authentication Protocol ) scheme is analyzed and a new identity authentication scheme SEAP is proposed. Comparing with other related schemes, the integrative performance of SEAP is improved greatly. The characteristics of SEAP are as follows: It supports short password, do not use encrypted algorithm between user and server to reduce computation overhead, and can resist dictionary, replay, and denial of service attacks. In addition, a remote identity authentication scheme using smart card based on discrete logarithm and EIGamal public key mechanism is presented. The scheme allows legal user to freely choose password in registration, proceeds communication once between user and server, does not ask server to store user’s password table, can resist replay attack using time stamp, and can overcome security weakness such as forgery attack in Hwang-Li scheme.Secondly, the security flaw in Ao-Chen-Bai group signature scheme is pointed out, namely, an attacker can construct a legal signature and implement a forgery attack to system, and similar attack is fit for Tseng-Jan II scheme. This thesis presents an improved group signature scheme based on Tseng method , which can resist forgery attack and be unlinkable, and overcomes the shortcomings of Ao-Chen-Bai group signature scheme and Tseng-Jan II scheme.In order to ensure the confidentiality, integrality, fairness, validity of data over network, a transmission-oriented electronic evidence andnon-repudiation protocol TEENP (transmission-oriented electronic evidence and non-repudiation protocol) is proposed. The thesis analyses the virtues and shortcomings of existed Electronic evidence and non-repudiation protocols FNP (Fair non-repudiation protocol) and CMP(Certified Electronic Mail Protocol), compares the performances between TEENP scheme and CMP scheme, extends the semantics and reasoning rulers of BAN logic. Furthermore, the non-repudiation of TEENP scheme is proved using BAN logic. Comparing with other correlative protocols, the security of TEENP is increased and the computation, communication overhead is reduced significantly.Finally, a key agreement scheme GDH.2 suitable for multi-user is analyzed thoroughly, the corresponding security shortcoming in GDH.2 is found, resulting an improved method M-GDH.2. Compared with GDH.2, the security of the proposed M-GDH.2 is greatly increased at a slight cost in implementation complexity, namely, the system satisfies "forward security" requirement, and can resist Denning-Sacco attack and replay attack. Subsequently, the dynamic change of communication entities is discussed. In addition, a secure communication system demo for three users is designed based on M-GDH.2 protocol, which allows users freely agree conversation key and use it to communicate with each other secretly.
【Key words】 Information security; Identity authentication; digital signature; Non-repudiation technique; Secrecy communication;