摘要
文章提出有可信第三方参与的认证协议中,存在一个第三方签名的新鲜性漏洞,并以NSPK协议、A(0)协议和NS签名协议为例,说明这种漏洞存在的普遍性,同时设计出了相应的攻击方法。最后,分析了这种漏洞产生的原因,并提出了在签名消息中加入时间戳的改进方法。
This paper puts forward a freshness defect of third party's signature in authentication protocol which has trusted third party. Making NSPK protocol, A(0) protocol and NS signature protocol as examples, the universality of this defect and design the corresponding attack methods are proposed. Finally, the cause of this defect is analyzed and the improved scheme is put forward by using timestamp.
出处
《计算机与数字工程》
2011年第7期105-108,共4页
Computer & Digital Engineering
基金
美国GeneChiu基金(编号:GFC2006-001)资助
关键词
认证协议
新鲜性
签名
协议攻击
时间戳
authentication protocol
freshness
signature
protocol attack
timestamp