WANG Bang-ju1, ZHANG Huan-guo1, WANG Yu-hua3. Secure password-based authentication scheme with anonymous identity without smart cards[J]. 2008, (10): 70-75.
WANG Bang-ju1, ZHANG Huan-guo1, WANG Yu-hua3. Secure password-based authentication scheme with anonymous identity without smart cards[J]. 2008, (10): 70-75.DOI:
安全的非智能卡匿名口令认证方案
摘要
对Rhee-Kwon-Lee非智能卡(SC)口令认证方案进行安全分析发现
此方案易受内部攻击
不能实现口令自由更换
并且计算效率不高。基于此提出了一种新的基于散列函数的非SC匿名口令认证方案
新方案采用匿名身份与口令混淆
并结合时间戳来提高安全性和计算效率。新方案弥补了Rhee-Kwon-Lee方案的安全缺陷。而且
与其他同类非SC方案相比较
新方案支持文中理想的非SC口令认证方案的所有安全需求
安全性能最好且计算量小。
Abstract
Rhee-Kwon-Lee’s password-based scheme without using smart cards is vulnerable to insider attack
password can’t be changed freely
and its computational cost is high.In order to fix all these security flaws
a new password-based authentication scheme with anonymous identity without using smart cards was presented.The security and computational efficiency of our scheme were improved by confusing the anonymous identity with user’s password and taking use of the timestamp.According to comparisons with other password authentication schemes without smart cards
our scheme not only fixes weaknesses of Rhee-Kwon-Lee’s scheme
but also satisfies all the security requirements for ideal password authentication without smart cards and is the better one in security performance and computational cost.