作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2006, Vol. 32 ›› Issue (17): 192-193,. doi: 10.3969/j.issn.1000-3428.2006.17.067

• 安全技术 • 上一篇    下一篇

一个简单有效的口令识别方案

袁 丁1;范平志2   

  1. 1. 四川师范大学计算机科学学院,成都 610066;2. 西南交通大学移动通信研究所,成都 610031
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2006-09-05 发布日期:2006-09-05

A Simple and Efficient Password Authentication Scheme

YUAN Ding1; FAN Pingzhi 2   

  1. 1. Computer Science College, Sichuan Normal University, Chengdu 610066; 2. Institute of Mobile Communication, Southwest Jiaotong University, Chengdu 610031
  • Received:1900-01-01 Revised:1900-01-01 Online:2006-09-05 Published:2006-09-05

摘要: 基于口令的身份识别技术是分布式网络环境中使用最为广泛的一种技术,然而传统的口令识别技术容易受到字典攻击、重传攻击和拒绝服务攻击。针对Sandirigara等人提出的SAS协议,提出了一种简单有效的口令识别方案SEPA,该方案可以抵御字典攻击、重传攻击和服务器拒绝服务攻击,且计算负荷和通信负荷较小。

关键词: 口令识别, Hash函数, 一次口令, 安全

Abstract: The identity authentication mechanism based on password protection is widely used in distributed environments. However, the traditional authentication scheme using passwords is vulnerable to attacks like dictionary attack, replay attack and denial of service attack. Based on the SAS protocol proposed by Sandirigara et al, this paper presents a simple and efficient password authentication scheme that can resist dictionary, replay, denial of service attacks, and minimize the computation and communication overheads.

Key words: Password authentication, Hash function, One-time password, Security