中国科学技术大学学报 ›› 2011, Vol. 41 ›› Issue (7): 589-593.DOI: 10.3969/j.issn.0253-2778.2011.07.004

• 原创论文 • 上一篇    下一篇

一个具有完备前向安全性的基于口令认证密钥协商方案

郝 卓   

  1. 中国科学技术大学电子工程与信息科学系,安徽合肥 230027
  • 收稿日期:2011-04-28 修回日期:2011-06-23 出版日期:2011-07-31 发布日期:2011-07-31
  • 通讯作者: 俞能海
  • 作者简介:郝卓,男,1985年生,博士生. 研究方向:计算机网络安全. E-mail: hzhuo@mail.ustc.edu.cn
  • 基金资助:
    国家科技重大专项(2010ZX03004-003)资助.

A password-authenticated key agreement scheme with perfect forward secrecy

HAO Zhuo   

  1. Department of Electronic Engineering and Information Science, University of Science and Technology of China, Hefei 230027, China
  • Received:2011-04-28 Revised:2011-06-23 Online:2011-07-31 Published:2011-07-31

摘要: 在基于网络的分布式环境中,基于口令的认证密钥协商方案是一项基本的安全防护机制.对一个已有的基于口令的认证密钥协商方案[Chen T H, Hsiang H C, Shih W K. Security enhancement on an improvement on two remote user authentication schemes using smart cards. Future Generation Computer Systems, 2011, 27(4): 337-380]做了安全分析,指出其易受离线口令猜测攻击,并且不具备完备的前向安全性.在此基础上,提出了一个安全性增强的远程口令认证密钥协商方案.所提出的方案继承了已有方案的优良性质,能够抵抗离线口令猜测攻击,并且具有完备的前向安全性.经过安全分析,论证了所提出的方案具有强安全性,适合于在分布式环境中对用户和服务器提供双向认证和密钥协商.

关键词: 认证密钥协商, 口令认证, 完备前向安全性, 离线口令猜测攻击

Abstract: In a distributed network environment, password-authenticated key agreement schemes are fundamental security mechanisms. A security analysis of Chen et al.s scheme [Chen T H, Hsiang H C, Shih W K. Security enhancement on an improvement on two remote user authentication schemes using smart cards. Future Generation Computer Systems, 2011, 27(4): 337-380] was presented. It was found that Chen et al.s scheme cannot resist offline password guessing attacks, and does not have perfect forward secrecy. A security enhanced password-authenticated key agreement scheme was thus proposed. The proposed scheme maintains the good properties of Chen et al.s scheme, is resistant to offline password guessing attack and provides perfect forward secrecy. A security analysis of the proposed scheme demonstrated that it is capable of strong security. It is suitable for providing mutual authentication and key agreement between the user and the server in a distributed environment.

Key words: authenticated key agreement, password authentication, perfect forward secrecy, offline password guessing attack