作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2020, Vol. 46 ›› Issue (9): 143-148. doi: 10.19678/j.issn.1000-3428.0055661

• 网络空间安全 • 上一篇    下一篇

基于双序列函数的重放攻击防御方案

赵梁, 李磊, 李向丽   

  1. 郑州大学 信息工程学院, 郑州 450000
  • 收稿日期:2019-08-05 修回日期:2019-10-08 发布日期:2019-10-18
  • 作者简介:赵梁(1996-),男,硕士研究生,主研方向为网络与信息安全;李磊,博士;李向丽,教授。
  • 基金资助:
    河南省科技攻关计划(172102210484)。

Replay Attack Defense Scheme Based on Double Sequence Function

ZHAO Liang, LI Lei, LI Xiangli   

  1. College of Information Engineering, Zhengzhou University, Zhengzhou 450000, China
  • Received:2019-08-05 Revised:2019-10-08 Published:2019-10-18

摘要: 针对Web应用服务端易受重放攻击的问题,提出一种基于双序列函数的Web服务端防御方案。分别利用序列函数和周期函数生成身份校验阶段和会话阶段的加密校验参数,并通过双端定义相同结构的序列函数进行双向认证,以序列值递进的方式进行参数更新,从而过滤重放攻击报文,保证请求的可靠性与新鲜性。分析结果表明,该方案可以避免网络延迟影响,具有良好的抗重放攻击能力。

关键词: 重放攻击, 服务器, 权限框架, 序列函数, 会话保持

Abstract: To address the problem that Web application servers are vulnerable to replay attacks,this paper proposes a defense scheme based on double sequence function for Web servers.The sequence function and periodic function are used to generate the encryption verification parameters in the identity verification stage and the session stage respectively,and the bidirectional authentication is carried out through the sequence functions with the same structure defined on both sides.The parameters are updated in the progressive way of sequence value,so as to filter messages of replay attacks and ensure the reliability and freshness of the request.Analysis results show that the scheme can avoid the influence of network delay and has good ability to resist replay attacks.

Key words: replay attack, server, authority framework, sequence function, session persistence

中图分类号: