摘要
讨论了2006年袁丁等人设计的简单高效的口令识别方案(SEPA),指出该方案无法抵御字典攻击、中间人攻击和服务器拒绝服务攻击。提出了一个基于智能卡的动态认证方案,并对其进行了分析,结果表明新方案提供双向认证,安全性高,运算量低,具有安全、友好、方便的口令更新方式,并且服务器不需维护用于认证的验证表。
This article discussed an authentication scheme recently advanced by Yuan Ding et al, and indicated that the scheme was vulnerable to dictionary attack, man-in-the-middle attack and denial-of-service attack to the server. And then a dynamic authentication scheme using smart card was proposed and analyzed. The analysis shows that the proposed new scheme, which provides mutual authentication, has the properties of high security and low computational cost, and that it supplies secure, friendly and convenient password-change phase and the server of the scheme does not need to maintain the verification tables used to help authentication.
出处
《计算机应用》
CSCD
北大核心
2008年第3期637-639,共3页
journal of Computer Applications
基金
现代通信国家重点实验室基金资助项目(51436020405JB5205)
关键词
动态认证
双向认证
智能卡
口令
dynamic authentication
mutual authentication
smart card
password