作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2009, Vol. 35 ›› Issue (24): 168-169. doi: 10.3969/j.issn.1000-3428.2009.24.055

• 安全技术 • 上一篇    下一篇

改进的一次性口令认证方案

徐成强,李作维   

  1. (山东交通学院信息工程系,济南 250023)
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2009-12-20 发布日期:2009-12-20

Improved Scheme of One-time-password Authentication

XU Cheng-qiang, LI Zuo-wei   

  1. (Department of Information Engineering, Shandong Jiaotong University, Jinan 250023)
  • Received:1900-01-01 Revised:1900-01-01 Online:2009-12-20 Published:2009-12-20

摘要: 对张宏,陈志刚提出的一种新型的一次性口令认证方案(计算机工程, 2003年第17期)进行分析,指出其存在重要数据存储、无法抵抗拒绝服务攻击等不安全隐患,结合一次性口令的简易性、密码学技术和USB Key介质对该方案进行改进,提出一种更加安全的认证方案,并对其进行安全性分析。结果表明,该方案具有操作简易性、保密性和存储安全性,且系统开销较小。

关键词: 一次性口令, 认证, 拒绝服务攻击

Abstract: After analysing one one-time-password authentication scheme proposed by Zhang Hong and Chen Zhigang, some insecurities such as data storage and can not resist denial of service attacks are pointed out. The scheme is improved with simplicity of one-time-passwords and cryptography technology and the USB Key media. A more secure authentication scheme is produced and the safety analysis is given. Results show that the sheme is easy to operate, secret and safety, and has less system consumption.

Key words: one-time-password, authentication, denial of service attack

中图分类号: