摘要
分析了段晓毅等人提出的动态ID的远程认证方案,发现该方案不能抵御离线密码字猜测攻击,重放攻击,冒充服务器攻击,且在相互认证后不能提供会话密钥。提出了一个改进方案,改进后的方案克服了以上的安全缺陷,且用户可自由选择登录系统的密码,相互认证后用户和服务器共享一个会话密钥。
In this paper, Duan et al.’s scheme is analyzed. It is showed that this scheme is insecure against offline-guessing attack, replay attack, forgery attack and a session key doesn’t be provided after mutual authentication. An improved scheme is proposed that overcomes the above-mentioned security flaws with not affecting the merits of the original scheme. The proposed scheme not only allows the users to choose and change their passwords freely, but also generates a session key agreed by the user and the server.
出处
《计算机工程与应用》
CSCD
2014年第22期126-129,共4页
Computer Engineering and Applications
基金
重庆市教育技术委员会项目(No.KJ121103)
重庆三峡学院科研项目(No.11ZD-15)
关键词
用户认证
智能卡
离线密码字猜测攻击
相互认证
user authentication
smart card
offline password guessing attack
mutual authentication