摘要
针对Lin和Lai提出的基于口令的远程用户鉴别方案在时间戳和用户ID上存在的脆弱性,提出基于挑战-应答机制的改进方案。该方案采用指纹和智能卡双重认证技术,能进行双向认证,可抵抗重放攻击和假冒攻击,且由示证和认证双方共同生成随机因子,也体现了认证的公平性,认证过程不需要传递用户指纹信息,保护了用户的隐私。
A password-based remote user authentication scheme was proposed by Lin and Lai, but there were some vulnerabilities in time-stamp and user ID, So an improved scheme based on challenge-response was presented, adopting diplex authentication technologies, fingerprint and smart card. It could achieve mutual authentication and avoid replay attack and masquerade attack. The random factor was generated by the mutual parties to guarantee the authentication fairness. Moreover, user's fingerprint needed not be transmitted in the authentication process to protect user's privacy.
出处
《计算机应用》
CSCD
北大核心
2005年第11期2554-2556,共3页
journal of Computer Applications
基金
国防科技重点实验室基金资助项目(51436050404QT2202)
关键词
身份认证
指纹识别
智能卡
假冒攻击
重放攻击
authentication
fingerprint verification
smart card
masquerade attack
replay attack