收稿日期: 2003-06-13
修回日期: 2003-12-12
网络出版日期: 2004-07-10
基金资助
国家自然科学基金项目(60273027);国家重点基础研究发展规划项目(G1999035802)资助
Advances in Security of WTLS Handshake Protocol
Received date: 2003-06-13
Revised date: 2003-12-12
Online published: 2004-07-10
邹学强 , 冯登国 . WTLS握手协议的安全性分析及改进[J]. 中国科学院大学学报, 2004 , 21(4) : 494 -500 . DOI: 10.7523/j.issn.2095-6134.2004.4.011
This paper analyzes the security of existing WTLS handshake protocol and points out the secure limitationand its corresponding threat.Then we propose a modified WTLS handshake protocol which can provide forwardsecrecy and user anonymity by using signcryption.Finally this paper makes a discussion of the security of modifiedprotocol.
Key words: signcryption; forward secrecy; user anonymity
[ 1 ] W A P Forum.Wi reless application protocol wireless t ransport layer securi ty specifi cation.Version 06-Apr-2001.
[ 2 ] C Gunther.An identity-based key-exchange protocol.In :Advances in Cryptology-Eurocrypto89.Springer-Verlag, 1990.29—37.
[ 3 ] W Diffie, P van Oorschot, M Wiener.Authentication and authenticated key exchanges.Designs Codes and Cryptography.1992.2 :107—125.
[ 4 ] M Bel lare, S K Miner.A forward-secure digital signature scheme.In :Advances in Cryptology-Crypto99.Springer-Verlag, 1999.
[ 5 ] DongGook Park, Colin Boyd, Sang-Jae Moon.Forward secrecy and i ts application to future mobile communications security.PKC2000, LNCS1751.Spring-Verlag, 2000.433 —445.
[ 6 ] K Lee, S Moon.AKA protocols for mobi le communications.In :Proceedings of 6th Aust ralasian Conference Information Security and Privacy ACISP2000.2000.400—411.
[ 7 ] K Lee, S Moon, W Jeong, T Kim.A-2-passauthentication and key agreement protocol f or mobi le communications.In :Proceedings of the2ndInternational Conference on Information Secur and Cryptology, ICISC99.1999.143 —155.
[ 8 ] F Bao, R H Deng.A signcryption scheme with signature di rect ly verifiable by public key.In :Proc of PKC98, LNCS 1431.1998.55—59
[ 9 ] Mitchell C J, Piper F, Wi ld P.Digital signatures.In :Cont emporary Cryptology, The Science of Information Integrity.IEEE Press,1992.325 —378
/
| 〈 |
|
〉 |