作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2006, Vol. 32 ›› Issue (6): 22-24.

• 博士论文 • 上一篇    下一篇

一种适合远程访问场景的认证和密钥交换方案

叶润国1,2,3,虞淑瑶1,2,3,冯彦君1,2,3,吴宇 1,2,3   

  1. 1. 中国科学院网络信息中心,北京 100080;2. 中国科学院计算所,北京 100080;3. 中国科学院研究生院,北京 100039
  • 出版日期:2006-03-20 发布日期:2006-03-20

An Efficient Asymmetric Authentication and Key Exchange Scheme

YE Runguo1,2,3, YU Shuyao1,2,3, FENG Yanjun1,2,3, WU Yu1,2,3   

  1. 1. Computer Network Information Center, CAS, Beijing 100080; 2. Institute of Computing Technology, CAS, Beijing 100080;3. Graduate School of the Chinese Academy of Sciences, Beijing 100039
  • Online:2006-03-20 Published:2006-03-20

摘要: 提出了一种基于基本ECMQV 协议的非对称式认证和密钥交换方案AEAS,可实现对客户端的口令认证和对服务端的公钥认证;AEAS 中的客户端口令认证具有零知识安全属性,允许用户使用弱口令,并能抵御各种字典攻击和重放攻击;与同类非对称认证和密钥交换方案相比,AEAS 具有最少的公钥计算开销。AEAS 协议能集成到现有WTLS 协议框架中,从而实现一种高安全性和低计算开销的WTLS扩展,它完全可满足无线终端在企业远程访问场景下的高安全性要求。

关键词: 网络安全;密钥交换方案;ECMQV;WTLS

Abstract: An ECMQV-based asymmetric authentication scheme is proposed, which enables client authentication with memorable passwords and server authentication with conventional certificates; the client password authentication possesses zero-knowledge-proof security property, which allows using weak passwords; implicit authentication is used to validate server-side entity, which greatly cuts down client computation overhead. AEAS can be integrated into current WTLS framework, resulting in a WTLS extension with higher security and lower computation overhead, which mets wireless terminals' high-security requirements under enterprise remote access scenario

Key words: Network security; Key exchange scheme; ECMQV; WTLS