节点文献
数据加密技术在网络安全中的应用研究
The Application Research of Data Encryption Technology in Network Security
【作者】 宋金秀;
【导师】 杨秋翔;
【作者基本信息】 中北大学 , 计算机应用技术, 2007, 硕士
【摘要】 随着全球信息化发展和Internet普及,计算机网络安全逐渐成为人们关注的焦点问题。网络上的数据传输应保证其机密性、可认证性、完整性及不可否认性。解决这些问题的唯一有效的手段就是使用现代密码技术。由此本文对现代密码技术作了详细的介绍,并重点介绍了椭圆曲线密码体制。由于身份认证是一个安全的网络系统的门户,并且为了有效地防止口令监听和传输泄露,安全专家提出了一次性口令认证技术(One-time Password Authentication)。作为对数据加密技术在网络安全中的应用,本文在研究现代密码学的基础上,提出了一种改进的一次性口令身份认证方案。为体现此方案的优越性,本文首先对一个典型的一次性口令认证方案—S/KEY口令序列认证方案进行了详细地描述和深入地研究,并指出其中所存在的部分安全缺陷。方案以挑战/应答机制为基础,基于安全单向散列函数与椭圆曲线密码体制而设计,是一种能有效适用于网络环境的一次性口令身份认证方案。该方案运用椭圆曲线密码体制生成共同的会话密钥,对传送密钥的信道的安全性要求降低了;每次认证都采用不同的会话密钥,安全性提高了;能够对通信双方实行相互认证;由用户端生成随机数,减少了服务器的开销。本方案克服了传统的挑战/应答方案的弱点,有效地保护了用户身份信息,能防止重放攻击、小数攻击、冒充攻击、穷尽攻击等常用攻击手段的攻击。本文的创新点就是使用椭圆曲线密钥交换机制生成共同的会话密钥,并且每次认证都采用不同的会话密钥,来加密客户与服务器之间传送的数据,从而提高了传送数据的安全性。基于此设计了一个改进的身份认证方案并实现了基于此方案的认证系统。本方案执行性能优良,安全性上有显著的提高。
【Abstract】 With the development of global information and the popularization of Internet, the security of computer network has become the focus of concern gradually. A network in which data was transmitted should promise the data’s confidentiality, authentication, identity and anti-negation. The only valid way to solve these problems is modern cryptology. Thus this paper has introduced modern cryptology in details, and introduced elliptic curve cryptology especially. For identity authentication is the gateway of a secure network system, to keep password from detecting and transmission leaking, the information security expert bring forward the technology of One-time Password Authentication. As an application of data encryption technology in network security, combined with Elliptic-curve cryptology, this paper proposed a new improved One-time Password Authentication Scheme on the base of modern cryptology.To embody the superiority of this scheme, first of all this paper describe the classic one-time password authentication scheme that is S/KEY authentication scheme, then point out the security flaws. Thus, based on the Challenge/Response system and depended on the safe one-way Hash function, the scheme was designed, which can be applied in the network environment effectively. Because of the mutual conversation key was produced by making use of ECC, the security requirement of channel in which the key is transmitted was decreased; in every authentication process, by using different communicating key to increase the security. This scheme can implement the two-way identity authentication; the spending of server was cut down by producing a random data in custom.This scheme conquered the flaws of traditional Challenge/Response system, protected the custom’s ID information effectively and can avoid some common attack means such as replay attack, mini number attack, imitate attack etc.The innovation in this paper is using ECC key exchange mechanism to produce the mutual key and in every authentication process using different key to encrypt the transmitted data, thus a new one-time password authentication design was proposed and carried out. This scheme has an excellent performance and a dramatically increased security.
- 【网络出版投稿人】 中北大学 【网络出版年期】2007年 05期
- 【分类号】TP393.08
- 【被引频次】14
- 【下载频次】852