欢迎访问中国科学院大学学报,今天是
论文

WTLS握手协议的安全性分析及改进

  • 邹学强 ,
  • 冯登国
展开
  • 信息安全国家重点实验室(中国科学院研究生院), 北京 100039

收稿日期: 2003-06-13

  修回日期: 2003-12-12

  网络出版日期: 2004-07-10

基金资助

国家自然科学基金项目(60273027);国家重点基础研究发展规划项目(G1999035802)资助

Advances in Security of WTLS Handshake Protocol

  • ZOU Xue-Qiang ,
  • FENG Deng-Guo
Expand
  • State Key Laboratory of Information Security, Graduate School of the Chinese Academy of Sciences, Beijing 100039, China

Received date: 2003-06-13

  Revised date: 2003-12-12

  Online published: 2004-07-10

摘要

对WTLS握手协议的安全性能进行分析,指出其存在的安全缺陷和可能产生的安全威胁,利用签名加密机制对握手协议进行了改进,以实现向前保密和用户匿名保护,最后对改进协议的安全性作了讨论.

本文引用格式

邹学强 , 冯登国 . WTLS握手协议的安全性分析及改进[J]. 中国科学院大学学报, 2004 , 21(4) : 494 -500 . DOI: 10.7523/j.issn.2095-6134.2004.4.011

Abstract

This paper analyzes the security of existing WTLS handshake protocol and points out the secure limitationand its corresponding threat.Then we propose a modified WTLS handshake protocol which can provide forwardsecrecy and user anonymity by using signcryption.Finally this paper makes a discussion of the security of modifiedprotocol.

参考文献

[ 1 ] W A P Forum.Wi reless application protocol wireless t ransport layer securi ty specifi cation.Version 06-Apr-2001.

[ 2 ] C Gunther.An identity-based key-exchange protocol.In :Advances in Cryptology-Eurocrypto89.Springer-Verlag, 1990.29—37.

[ 3 ] W Diffie, P van Oorschot, M Wiener.Authentication and authenticated key exchanges.Designs Codes and Cryptography.1992.2 :107—125.

[ 4 ] M Bel lare, S K Miner.A forward-secure digital signature scheme.In :Advances in Cryptology-Crypto99.Springer-Verlag, 1999.

[ 5 ] DongGook Park, Colin Boyd, Sang-Jae Moon.Forward secrecy and i ts application to future mobile communications security.PKC2000, LNCS1751.Spring-Verlag, 2000.433 —445.

[ 6 ] K Lee, S Moon.AKA protocols for mobi le communications.In :Proceedings of 6th Aust ralasian Conference Information Security and Privacy ACISP2000.2000.400—411.

[ 7 ] K Lee, S Moon, W Jeong, T Kim.A-2-passauthentication and key agreement protocol f or mobi le communications.In :Proceedings of the2ndInternational Conference on Information Secur and Cryptology, ICISC99.1999.143 —155.

[ 8 ] F Bao, R H Deng.A signcryption scheme with signature di rect ly verifiable by public key.In :Proc of PKC98, LNCS 1431.1998.55—59

[ 9 ] Mitchell C J, Piper F, Wi ld P.Digital signatures.In :Cont emporary Cryptology, The Science of Information Integrity.IEEE Press,1992.325 —378

文章导航

/