摘要
客户端-服务器认证协议的匿名性指服务器能够认证客户端的真实性,但无法获知客户端的身份。针对认证协议提出了新的安全性需求—不可链接性,该性质是对匿名性的有益补充。对已有文献中的认证协议进行修正,使其在不降低认证效率的前提下满足不可链接性。修正后的方案同时提供身份保护性、不可链接性、双向认证、密钥协商、密钥更新、会话密钥的后向保密性以及客户端的口令修改功能。
In a client-server authentication protocol,anonymity means that the server could not know the identity of the client,although be able to authenticate the client. This paper,for authentication protocols,proposes a special requirement—unlinkability,which serves as a complement to the anonymity,and the security of the design in certain paper is strengthened by addressing the unlinkability without reducing the authentication efficiency. The resulting amendment provides the functions of identity protection,unlinkability,mutual authentication,key exchange,key update,key backward secrecy and password modification.
出处
《信息安全与通信保密》
2010年第7期78-80,共3页
Information Security and Communications Privacy
基金
国家自然科学基金资助项目(批准号:60703031
60703004)
国家863计划资助项目(编号:2008AA01Z403)
关键词
无线通信
用户认证
匿名性
不可链接性
wireless communication
user authentication
anonymity
unlinkability