作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2008, Vol. 34 ›› Issue (20): 144-145. doi: 10.3969/j.issn.1000-3428.2008.20.052

• 安全技术 • 上一篇    下一篇

一种有效的图像口令身份认证方案

陈 平,申永军,徐华龙   

  1. (兰州大学信息科学与工程学院,兰州 730000)
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2008-10-20 发布日期:2008-10-20

Efficient Graphical Password Authentication Method

CHEN Ping, SHEN Yong-jun, XU Hua-long   

  1. (Institute of Information Science & Engineering, Lanzhou University, Lanzhou 730000)
  • Received:1900-01-01 Revised:1900-01-01 Online:2008-10-20 Published:2008-10-20

摘要: 分析和比较一次性口令和图像口令的相关技术,指出在开放网络环境下进行身份认证时,图像口令存在的缺陷,并论证采用一次性口令弥补该缺陷的可行性和可靠性。基于一次性口令产生的会话密钥,设计一种有效的图像口令身份认证方案。该方案提高口令的安全性,能够防止窥探攻击和重放攻击。类似技术被应用于更加灵活的实际环境中,并增强了应用系统的安全性。

关键词: 认证, 图像口令, 一次性口令, 可视化哈希

Abstract: This paper analyzes one-time-password and graphical password, and discusses some shortcomings of graphical password in the case of authentication through an open network. This paper proposes an improved method of high feasibility, reliability to remedy these shortcomings which based on the one-time-password, which enhances the security of the password and avoid replay attack and shoulder-surfing attack. Similar techniques can be used to boost up the security of the application security systems for more flexible application.

Key words: authentication, graphical password, one-time-password, visual hash

中图分类号: