作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2012, Vol. 38 ›› Issue (06): 153-155. doi: 10.3969/j.issn.1000-3428.2012.06.050

• 安全技术 • 上一篇    下一篇

基于ECDSA的三方口令认证密钥交换协议

王国才,柯福送,王 芳   

  1. (中南大学信息科学与工程学院,长沙 410083)
  • 收稿日期:2011-07-29 出版日期:2012-03-20 发布日期:2012-03-20
  • 作者简介:王国才(1963-),男,副教授,主研方向:网络通信,信息安全;柯福送、王 芳,硕士
  • 基金资助:
    国家自然科学基金资助项目(60773013)

ECDSA-based Password Authenticated Key Exchange Protocol for Three-party

WANG Guo-cai, KE Fu-song, WANG Fang   

  1. (School of Information Science and Engineering, Central South University, Changsha 410083, China)
  • Received:2011-07-29 Online:2012-03-20 Published:2012-03-20

摘要: 提出一种基于椭圆曲线数字签名算法(ECDSA)的三方口令认证密钥交换协议。将ECDSA分为公钥生成、签名过程和验证过程 3个阶段,在此基础上,设计协议过程、双向认证机制,使任意2个用户通过服务器能进行身份认证和密钥交换。分析结果表明,该协议能降低计算难度和存储开销,抵抗字典攻击和服务器泄露攻击。

关键词: 口令认证密钥交换, 字典攻击, 椭圆曲线数字签名算法, 重放攻击

Abstract: In order to against dictionary attack and server compromise attack, this paper proposes a Elliptic Curve Digital Signature Algorithm(ECDSA)-based password authenticated key exchange protocol for three-party. ECDSA is divided into public key generation, signature verification process and verification process. On the bases of it, this protocol is divided into six steps, and designs mutual authentication mechanism. And any two clients can accomplish key exchange relying on the server. Analysis results show that this protocol can reduce the calculation difficulty and storage cost, and can resist dictionary attacks and server compromise attack.

Key words: Password Authenticated Key Exchange(PAKE), dictionary attack, Elliptic Curve Digital Signature Algorithm(ECDSA), replay attack

中图分类号: