摘要
分析了Hu等人提出的基于智能卡的远程身份鉴别方案,发现该方案易遭受重放攻击和口令猜测攻击;提出了一种基于质询/响应和用户通行密语的改进方案,改进方案能抵抗重放攻击、口令猜测攻击、假冒服务攻击,同时具有较好的可修复性,最后对Hu方案和改进方案的效率进行了比较。改进方案保留了原方案中使用智能卡的优点,且具有更高的安全性。
A remote authentication scheme using smart cards proposed by Hu et al. is studied, and found that this scheme easily suffers replay attack and guessing attack. A modified scheme based on inquiry/response and user access secret is proposed, whicb can avoid replay attack, password guessing attack, masquerading server attack effectively. Moreover, it has a good repairability. The efficiency of Hu's scheme and the efficiecy of the modified scheme are compared finally. The modified scheme retains the advantage of using smart cards by the original scheme while strengthens the security.
出处
《通信技术》
2009年第1期333-335,共3页
Communications Technology
关键词
远程身份鉴别
智能卡
质询/响应
用户通行密语
可修复性
remote user authentication: smart cards
inquiry/response: user access secret
repairability