作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2006, Vol. 32 ›› Issue (6): 146-147,162.

• 安全技术 • 上一篇    下一篇

一种安全高效的强口令认证协议

虞淑瑶1,2,3,叶润国1,2,3,张友坤4,宋成 2   

  1. 1. 中科院计算技术研究所,北京100080;2. 中科院网络信息中心,北京 100080;3. 中科院研究生院,北京 100080;4. 清华大学软件学院,北京 100084
  • 出版日期:2006-03-20 发布日期:2006-03-20

A Hash-based Secure Strong-password Authentication Protocol

YU Shuyao1,2,3, YE Runguo1,2,3, ZHANG Youkun4, SONG Cheng2   

  1. 1. Institute of Computing Technology, CAS, Beijing 100080; 2. Network Information Center, Beijing Chinese Academy of Sciences, Beijing 100080;3. Graduate School of CAS, Beijing 100080; 4. School of Software, Tsinghua University, Beijing 100084
  • Online:2006-03-20 Published:2006-03-20

摘要: 提出了一种基于轻量级客户端的、基于散列函数的、用户端和服务器端双向基于口令的认证协议SPAS。指出了以往类似协议中存在的攻击问题,并分析了SPAS 的安全性, 指出 SPAS 能够抵御拒绝服务攻击、重放攻击、冒充攻击、服务器端验证信息泄密后的攻击。SPAS 协议能够应用于各种使用轻量级用户端的、在公共信道上进行认证的用户认证应用场景。

关键词: 认证;口令;散列函数;OSPA;SPAS

Abstract: Based on the analysis of OSPA protocol, which is a typical hash-based strong-password authentication protocol, this paper presents a hash-based strong-password mutual authentication scheme-SPAS. SPAS is resistant to DoS attacks, replay attacks, impersonation attacks, and stolen-verifier attacks. It expects SPAS can be employed in application scenarios where lightweight and secure user authentication scheme is required.

Key words: Authentication; Password; Hash; OSPA; SPAS