节点文献
一次性口令身份认证方案的设计与实现
A Designing and Implementation of One-Time Password Authentication Scheme
【作者】 索望;
【导师】 方勇;
【作者基本信息】 四川大学 , 通信与信息系统, 2005, 硕士
【摘要】 计算机网络是一个开放的系统。但由于其开放性导致计算机网络中存在相当多的安全漏洞和安全威胁,网络中的各类资源很容易被人非法访问和复制。因此,对网络资源访问者的合法身份进行认证就变得非常的重要,身份认证技术已经成为网络系统安全中最重要的技术之一。 较为常用的身份认证技术是基于静态口令的身份认证技术,该技术的特点是简单、易用,在一定的安全程度上可以进行有效的用户身份认证。但是,随着网络应用的深入化和网络攻击手段的多样化,静态口令认证技术由于其自身的安全缺陷已经不再适应于安全性要求较高的网络应用系统。静态口令认证技术面临的主要网络攻击手段有:明文形式的口令在网络上传输容易遭受口令窃听攻击;加密形式的口令则容易遭受截取/重放攻击;其他攻击手段还包括伪造主机攻击、内部人员攻击、字典攻击等等。 针对静态口令认证技术存在的安全缺陷,业界提出了一次性口令认证技术(One-Time Password Authentication),也称为动态口令认证技术。一次性口令认证技术是指用于认证用户合法身份的口令是一次性的,即每个口令都只是使用一次,每次认证都是使用不同的口令。这里所指的口令并不是用户口令,而是由用户口令和其他不确定因子计算所得的认证口令。一次性口令认证技术消除了静态口令认证技术的大部分安全缺陷,能有效抵抗静态口令认证技术所面临的主要安全威胁和攻击,为网络应用系统提供了更加安全可靠的用户身份认证保障。 本文首先对一次性口令认证技术的基本原理、实现方式和安全性进行了深入的分析。在此基础上,对两个典型的一次性口令认证方案—S/KEY口令序列认证方案和SAS-2认证方案进行了详细地描述和深入地研究。通过研究这些认证方案的工作过程,分析了这些认证方案以及其改进方案的安全性,并指出其中所存在的部分安全缺陷。在综合上述一次性口令认证方案及改进方案的基础上,本文提出了一种新型的一次性口令认证方案—NOTP认证方案(New One-Time Password Authentication Scheme),并实现了基于此方案的新型一次性口令认证系统—NOTP认证系统。NOTP认证方案具有认证步骤简单、执行性能优异、无需重新初始化、用户可任意修改口令等特点。同时,NOTP认证方案还增强了抵御各种
【Abstract】 The computer network is an open system. But, the open character brings on so many security vulnerabilities and attacks. The network resources can be accessed and copied by the lawless way easily. So it is very important to carry through the identity authentication for people who want to access the network resources.The technology of identity authentication basing on the static password is in common use. The characteristic of this technology is be easy to use and authenticating the users’ identity safely and availably. With the applications of network develop deeply and the means of attacking become more various, the technology of static password authentication is not be applied for the network system which needs the upper requires of security because of it’s security vulnerabilities.The main attack means to the static password authentication technology are: the users’ non-cryptograph password caa be wiretapped from the network and the cryptograph password can be suffered record/replay attack. Other attacks means include forge host attack, inside attack and dictionary attack etc.The information security experts bring forward the technology of One-Time Password Authentication for the static password authentication’s security vulnerabilities. This technology means the password for identity is only be used one time and differently every time. At this, the password is not the users’ password that like in the static authentication.This password is calculated from the users’ password and random genes.The One-Time Password authentication technique avoids the security vulnerabilities and offers safety authentication much more.First of all, the thesis research and analyze the basic theory, implement and security of the one-time password authentication technology. Base the research and analysis the thesis describe the classic two one-time password authentication schemes that are S/KEY authentication scheme and SAS-2 authentication scheme in details, and research these schemes thoroughly. Then the thesis point out the security flaws of these authentication schemes and improved schemes viaresearch the work flow and analyzes the security of these schemes. Synthesize the strongpoint of the classic authentication schemes, the thesis design a new one-time password authentication scheme, named NOTP authentication scheme and implement the NOTP authentication system base the new scheme. The specialties of the new scheme are simple process, excellent performance, not needs initialization anew and user can modify password freely. In addition the NOTP authentication scheme improves the resistance to the attacks and to be more security.The innovation in this article is bringing out a new One-Time Password Authentication design base on SAS-2 and carrying out the NOTP authentication system. There is the similarity between the two designs. The new design holds the SAS-2’s strongpoint in performable function and at the same time improves on security.
【Key words】 Identity authentication; one-time password authentication; Hash function; S/KEY; SAS-2; NOTP;
- 【网络出版投稿人】 四川大学 【网络出版年期】2006年 01期
- 【分类号】TP393.08
- 【被引频次】42
- 【下载频次】1058