摘要
实体间的身份认证和鉴别是电子支付协议的基础.近年来研究工作者提出了一系列的身份认证协议,但是都存在一定的不足.2005年,Ren_Junn Hwang提出了一个高效的适用于移动网络的域间身份认证协议,虽然他利用BAN逻辑证明了其安全性,但通过几个模拟攻击过程,依然可以发现该协议仍存在着一些安全漏洞和不足.本文给出了一种新的改进方案,使改进后的协议具备了以上这些特征.最后将改进后的协议应用于Yong Zhao提出的电子支付协议中,弥补了该支付协议中用户和仲裁机构没有身份认证的不足.
Identification and authentication is the foundation of electronic payment. In recent years, several authentication protocols are proposed, while most of them have some shortcomings. Ren-Junn Hwang put forward an inter-domain authentication protocol in 2005, which fits for mobile network. Although the protocol's security is proved with BAN logic, we can also find a few secure holes after some simulation attacks. In this paper, an improved protocol is given, which satisfies the above characters. Finally, the improved protocol is used to the electronic payment scheme proposed by Yong Zhao in which there is no authentication between user and arbitrage.
出处
《北京交通大学学报》
EI
CAS
CSCD
北大核心
2006年第5期28-31,共4页
JOURNAL OF BEIJING JIAOTONG UNIVERSITY
基金
国家自然科学基金资助项目(51436040203DZ01)
国家"973"项目(TG1999053801)
关键词
身份鉴别
移动电子支付
域间认证
identification and authentication
mobile electronic payment
inter-domain authentication