节点文献

智能卡安全技术的探索与改进

The Explore and Improvement of Smart Card Security Technology

【作者】 党岚君

【导师】 寇卫东;

【作者基本信息】 西安电子科技大学 , 通信与信息系统, 2005, 硕士

【摘要】 随着芯片技术的发展和应用安全性要求的提高,智能卡以其独特的安全性,在诸多领域中有着十分广泛的应用,如金融、社保、市政、加油等。因此,我们应该更加关注智能卡的安全。 在这些应用中,智能卡与读写器之间的认证和安全通信是重中之重。本文重点研究了有关智能卡的一些认证问题。 首先,本文给出了智能卡的一些基础知识和基本技术;然后回顾了一下智能卡已有的安全技术和机制;最后提出了两个带有会话密钥交换的认证协议,另外对非对称性单边认证做出了改进使其能够在重放攻击、主动攻击和恶意攻击下正常工作。 智能卡与读写器之间通信链路的加密是智能卡安全中一个重要的话题,其中一个基本的问题就是密钥的安全分发。在这篇论文中为了解决会话密钥产生和分发的问题,我提出了两个改进的双边对称性认证机制,并给出了安全性分析。 在对智能卡的认证协议进行安全分析时,我们主要考虑两种攻击,一种是重放攻击,一种是主动攻击。这两种攻击的目的都是尽量使伪卡的认证成功。除了这两种攻击,还有一种可能存在的攻击叫恶意攻击,它的目的仅仅是让真卡的认证失败。在考虑这三种攻击的情况下,智能卡的认证协议可能不能正常运转。在论文中,为了使认证协议能够抵抗这三种攻击,通过对经典的单边非对称性认证协议进行了改进,本论文提出了一种改进的认证协议。相应的安全性分析明确给出了考虑这三种攻击时,改进的认证协议比以前的协议更加强健。

【Abstract】 With the development of chip technology and the improvement of security requirements of applications, smart cards are often used in different applications that require strong security protection and authentication, such as identification, banking, and transportation. In a conclusion, we should pay more attention to the smart card security.In these applications, main focuses are on the authentication and secure communication links between cards and readers.First of all, an overview of smart card is given, and then the security schemes of smart card and attacks on it are reviewed. Finally, I propose two new authentication schemes including the session key exchange and data integrity protection. A new unilateral asymmetric authentication protocol is also proposed which can resistant to the combination of three kinds of attacks.Encryption of the card/card reader communications link is an important issue of smart card security, and a fundamental problem of all crypto logical procedures is the secure distribution of the secret key. To overcome the problem of session key generation and distribution, in this paper, two improved mutual symmetric authentication schemes are proposed. The schemes include session key exchange for secure messaging. Security analyses to the new schemes are provided.In security analyses of authentication protocols for smart cards, we usually consider two possible attacks: replay attacks and active attacks. The aims of both attacks are to try to use fake cards for successful authentication. In addition to these attacks, there are other possible attacks, the aim of which is only to let the valid cards to be unsuccessfully authenticated. These attacks are referred to as hostile attacks. The smart card authentication protocols may face a challenge of not functioning properly with the hostile attacks, the replay attacks and active attacks. In this paper, I proposed an improved authentication protocol by modifying a classic unilateral asymmetric authentication protocol to provide a strong protection to prevent the smart cards from these three kinds of attacks. The security analyses show that the improved authentication protocol is much stronger against these three kinds of attacks than the traditional protocol.

【关键词】 智能卡认证安全攻击
【Key words】 Smart cardauthenticationsecurityattacks
  • 【分类号】TN409
  • 【被引频次】24
  • 【下载频次】766
节点文献中: