摘要
基于口令的身份认证机制是分布式系统安全体系的重要组成部分。利用一个无需求逆的广义椭圆曲线签名算法构造了一个动态远程用户认证方案:GECSA方案。该方案基于“质询响应”机制,无需时戳,其安全性基于单向Hash函数和椭圆曲线离散对数计算的困难性,包括注册阶段、登录阶段、认证阶段和更改口令阶段,允许用户自主选择并更改口令,实现了双向认证;具备完备性和不可转让性,是一个低开销的、安全的远程用户认证机制。
Password-based user authentication scheme is the key part of the security infrastructure in a distributed system. A generalized elliptic curve signature scheme is presented. A novel remote user authentication scheme--GECSA, which is based on the generalized elliptic curve signature and has no inverse operation, is also proposed. The scheme uses challenge-response method, has no timestamps, relies on Hash function and discrete logarithm problem over the points on the elliptic curve to ensure the security. In addition, the scheme has four phases: registration phase, login phase, authentication phase and password change phase. Furthermore, the scheme has many merits: it enables users to freely choose and change password, provides mutual authentication between two entities, has much lower computational cost, and is sound and untransferable. In a word, the proposed scheme is a better scheme with lower cost and higher security.
出处
《系统工程与电子技术》
EI
CSCD
北大核心
2006年第10期1569-1571,共3页
Systems Engineering and Electronics
基金
国家自然科学基金资助课题(60271012)
关键词
用户认证
口令
智能卡
广义椭圆曲线签名算法
user authentication
password
smart cards
generalized elliptic curve signature scheme