一次性口令系统是目前网上流行的简单用户认证方案,能够有效解决用户密码在网上明文传送的不安全性。分析了现有的几种一次性口令系统,指出服务端的不安全性、对S/KEY的小数攻击等问题,在此基础上提出并实现了双向认证一次性口令协议TAO...一次性口令系统是目前网上流行的简单用户认证方案,能够有效解决用户密码在网上明文传送的不安全性。分析了现有的几种一次性口令系统,指出服务端的不安全性、对S/KEY的小数攻击等问题,在此基础上提出并实现了双向认证一次性口令协议TAOTP(Two-way Authenticate One Time Password),采用单向函数,通过客户端和服务端实现的双向认证,解决了服务端存储用户口令的不安全性和小数攻击等问题。展开更多
Some usual one-time password authentication protocols are analyzed. A practical efficient one-time pass-
word authentication implementing method is presented based on the symmetric algorithm, which conquers usual chal...Some usual one-time password authentication protocols are analyzed. A practical efficient one-time pass-
word authentication implementing method is presented based on the symmetric algorithm, which conquers usual chal-
lenge-response protocol weakness and can protect user's identity and avoid replay attack etc. It also can boost up the
security of the application security system by integrating with it in networks. And the correlative issues are discussed
deeply such as security, reliability and so on.展开更多
文摘一次性口令系统是目前网上流行的简单用户认证方案,能够有效解决用户密码在网上明文传送的不安全性。分析了现有的几种一次性口令系统,指出服务端的不安全性、对S/KEY的小数攻击等问题,在此基础上提出并实现了双向认证一次性口令协议TAOTP(Two-way Authenticate One Time Password),采用单向函数,通过客户端和服务端实现的双向认证,解决了服务端存储用户口令的不安全性和小数攻击等问题。
文摘Some usual one-time password authentication protocols are analyzed. A practical efficient one-time pass-
word authentication implementing method is presented based on the symmetric algorithm, which conquers usual chal-
lenge-response protocol weakness and can protect user's identity and avoid replay attack etc. It also can boost up the
security of the application security system by integrating with it in networks. And the correlative issues are discussed
deeply such as security, reliability and so on.