摘要
通过改进鉴别方案的安全策略和身份鉴别信息,提出了一种基于USB Key的可有效对抗离线口令猜测攻击和内部攻击的改进方案。安全性分析表明,改进后的方案保持了非存储数据型鉴别方案特点,且没有增加计算代价,具有更好的安全性和实用性。
Yen-Cheng Chen et al. proposed an efficient nonce-based authentication scheme with key agreement in 2005. However, this authentication scheme has been found to be vulnerable to power analysis attack, off-line password guessing attack and internal attack. To solve this problem, an improved USB-Key-based authentication scheme is proposed, which can withstand the off-line password guessing attack and internal attack by means of improving the security policy and authentication information. The security analysis shows that the improved scheme still keeps the features of the non-storage data model authentication scheme and will not add the additional computation cost to the smart card. It will perform better in security and practical operations.
出处
《信息与电子工程》
2009年第2期156-158,167,共4页
information and electronic engineering
关键词
电子钥匙
鉴别
离线口令猜测攻击
内部攻击
密钥协商
USB Key
authentication
off-llne password guessing attack
internal attack
Key agreement