作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2008, Vol. 34 ›› Issue (20): 149-150. doi: 10.3969/j.issn.1000-3428.2008.20.054

• 安全技术 • 上一篇    下一篇

基于混合密码的增强型3G终端入网认证方案

刘 莹,陆松年,杨树堂   

  1. (上海交通大学现代通信技术研究所,上海 200240)
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2008-10-20 发布日期:2008-10-20

Enhanced Access Authentication Scheme in 3G Network Based on Hybrid Encryption

LIU Ying, LU Song-nian, YANG Shu-tang   

  1. (Modern Communication Technology Researching Institute, Shanghai Jiaotong University, Shanghai 200240)

  • Received:1900-01-01 Revised:1900-01-01 Online:2008-10-20 Published:2008-10-20

摘要: 针对3G入网认证中存在的安全漏洞,利用PKI的密钥验证协议管理方便的特点,提出适用于B3G环境下的安全分层管理体系结构。同时结合此体系,采用椭圆曲线算法将对称和非对称加密有机结合,提高了协议的安全性,防止了用户身份的泄漏。通过与Zheng Yu、Georgios Kambourakis等人提出的方案进行比较,证明了相较于前者该方案虽增加了1次哈希计算,却减少了3次对称加密,而相较于后者不仅没有给终端带来计算负担,还减少了6次以上空中接口通信。

关键词: PKI体系, 用户身份标识, 混合密码, 密钥验证协议, 3G入网认证

Abstract: To solve security bugs of access authentication in 3G and take advantage of convenience of Authentication and Key Agreement(AKA) in PKI, a new certificate authority chain is introduced, which can well satisfy B3G hierarchical security. Based on this chain and elliptic curve cryptography, symmetric and asymmetric cryptography is properly combined which successfully prevents disclosure of user’s identity. Through comparing with schemes suggested by Zheng Yu, Georgios Kambourakis, et al, it is proved that for the former, this scheme has reduced three computations of asymmetric cryptography although adding one Hash. And as to the latter, it has decreased more than six times of transmission in the air but does not bring computation burdens to terminal.

Key words: PKI system, International Mobile Subscriber Identification(IMSI), hybrid encryption, Authentication and Key Agreement(AKA), 3G access authentication

中图分类号: