首页 | 官方网站   微博 | 高级检索  
     

适用于移动商务环境的口令认证密钥交换协议
引用本文:范亚军,温巧燕,金正平.适用于移动商务环境的口令认证密钥交换协议[J].北京邮电大学学报,2010,33(6):64-67.
作者姓名:范亚军  温巧燕  金正平
作者单位:北京邮电大学,网络与交换技术国家重点实验室,北京,100876;北京邮电大学,网络与交换技术国家重点实验室,北京,100876;北京邮电大学,网络与交换技术国家重点实验室,北京,100876
摘    要:在移动商务环境下为了解决全自动区分计算机和人类的公开图灵测试(CAPTCHA)技术易被攻击而失效的问题,提出了适用于该环境的口令认证密钥交换协议.将认证密钥交换过程与CAPTCHA挑战/应答过程巧妙融合,在不增加协议通信轮数的条件下,通过对称加密方案保护CAPTCHA问题实例;采用适于移动终端的椭圆曲线公钥系统,基于智能卡的安全特性,提高了协议的效率和安全性;在随机预言机模型下,给出了安全性证明.与同类协议相比,新协议仅需3轮通信就能使CAPTCHA问题实例免受攻击,无须存储口令验证表,具备前向安全性.

关 键 词:口令认证密钥交换  全自动区分计算机和人类的公开图灵测试  椭圆曲线公钥系统  智能卡
收稿时间:2010-03-31

A Password-Based Authenticated Key Exchange Protocol for Mobile-Commerce Environments
FAN Ya-jun,WEN Qiao-yan,JIN Zheng-ping.A Password-Based Authenticated Key Exchange Protocol for Mobile-Commerce Environments[J].Journal of Beijing University of Posts and Telecommunications,2010,33(6):64-67.
Authors:FAN Ya-jun  WEN Qiao-yan  JIN Zheng-ping
Abstract:For mobile commerce environments, a novel password based authenticated key exchange protocol is proposed to solve that the technology to effectively prevent legitimate users’ abuse, named as completely automatic public Turing test to tell computer and human apart (CAPTCHA), is vulnerable to analytical attacks. The protocol elaborately combines the CAPTCHA challenge/response progress with the authenticated key exchange interaction. It introduces symmetric encryption scheme to make CAPTCHA secure without additional communication rounds. And it is based on smart cards to obtain stronger security and adopts elliptic curve cryptosystem which is suitable for the environments. In random oracle model it is provably secure. Compared with the other related protocols, it requires only three communication rounds, protects CAPTCHA against analytical attacks, needs no validation tables storing on the server and provides perfect forward secrecy.
Keywords:password based authenticated key exchange  completely automatic public Turing test to tell computer and human apart  elliptic curve cryptosystem  smart card
本文献已被 万方数据 等数据库收录!
点击此处可从《北京邮电大学学报》浏览原始摘要信息
点击此处可从《北京邮电大学学报》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司    京ICP备09084417号-23

京公网安备 11010802026262号