节点文献
基于口令的认证:协议和应用
【作者】 陈开渠;
【导师】 冯登国;
【作者基本信息】 中国科学院软件研究所 , 计算机应用技术, 2001, 硕士
【摘要】 口令是一种常用的认证机制,为了提高安全性,人们基于口令设计了大量的认证机制,但现有的基于口令的认证机制大都存在猜测攻击的隐患。本文旨在Diffie-Hellman 密钥交换协议的基础上设计一个基于口令的认证机制,其特点是能够防止猜测攻击。 根据用户─用户和客户端─服务器这两种不同的认证环境,本文提出了对称的 SymPassword 协议和非对称的 AsyPassword 协议,分别适应于这两种环境。AsyPassword 在服务器被攻破的情况下,仍然具有一定的安全性,但是复杂度比SymPsaaword 要高一点。 在随机预言机安全通信模型上,本文证明了SymPassword和 AsyPassword是符合要求的基于口令的认证密钥交换协议。 本文在 IPSec 的密钥交换协议 IKE 中引入了基于SymPassword和AsyPassword的两种认证方式,在 TLS 中引入了基于 AsyPassword的认证方式。
【Abstract】 Password is widely used as an authentication mechanism. But nowadays mostpassword-based authefltication protocol are not secure against Guessing Attack. Forthis reason, we modify the famous Diffie-Hellman Key Exchange to providepassword-based authenticated key exchange against Guessing Attack.We design two protocol: SymPassword and AsyPassword. They suit forsymmetric user-user authenhcation and asymmetric client/server authentication,respectively. The AsyPassword protocol can provide some security against servercomprmise, but is more complex than SymPassword.On the Random Oracle Model which focuses on distribued securitycommunication, we prove tha SymPassword and AsyPassword are both securepassword-based authereicated key exchange protocol.At last, we modify the IKE protocol to add tWo authentication methods whichare based on SymPassword and AsyPassword respectively, and modify TLS protocolto add an anthentication method which is based on AsyPassword.
【Key words】 Password; Authentication Protocol; Diffie-Hellman Problem; Guessing Attacking; IPSec; SSL; TLS;
- 【网络出版投稿人】 中国科学院软件研究所 【网络出版年期】2002年 01期
- 【分类号】TP393.08;TP393.04
- 【被引频次】1
- 【下载频次】238