欢迎访问中国科学院大学学报,今天是
论文

一个远程口令鉴别方案的分析

  • 方根溪 ,
  • 戴宗铎 ,
  • 杨君辉
展开
  • 1. 中国科学技术大学研究生院信息安全国家重点实验室, 北京 100039;
    2. 中国科学院软件所, 北京 100080
方根溪,男,1978年6月牛,硕士

收稿日期: 2002-06-03

  网络出版日期: 2002-05-18

基金资助

973基金资助项目(G1999035804);国家自然科学基金资助项目(60173016)

Cryptanalysis of a Remote Password Authentication Scheme

  • FANG Gen-Xi ,
  • DAI Zong-Duo ,
  • YANG Jun-Hui
Expand
  • 1. SKLOIS, Graduate School of USTC, Beijing 100039;
    2. Institute of Software, CAS, Beijing 100080

Received date: 2002-06-03

  Online published: 2002-05-18

摘要

对谭凯军等提出的基于矢积的远程口令鉴别方案进行了安全性分析,指出攻击者为了冒充用户的登录请求,只须截获该用户的两次登录请求,或者只须再申请一张智能卡,取出其中有关信息后截获一次登录请求,因而该方案不安全.针对上述两种攻击,也对该方案提出了一些修改意见.

本文引用格式

方根溪 , 戴宗铎 , 杨君辉 . 一个远程口令鉴别方案的分析[J]. 中国科学院大学学报, 2002 , 19(3) : 229 -232 . DOI: 10.7523/j.issn.2095-6134.2002.3.002

Abstract

This paper analyzes the security of Tan's scheme for remote password authentication based on cross-product. We point out that to impersonate one user's log-in reguest, the intruders need only to know the user's two log-in requests, or need only to know one log-in request after booking a smart card and getting some useful information from it, so the scheme is not secure. Some modifications to Tan's scheme for avoiding the above two kinds of possible attacks are given.

参考文献

1. Evans A, Kantrowitz W. A User Authentication Scheme not Requiring Secrecy in the Computer. Comet ACM, 1974, 17(8):437^-442

2. Lennon K E, Matyas S M. Cryptographic Authentication of Time-invariant Quantities. IEEE Trans Comet, 1981,24(11):773一777

3. l,amport L. Password Authentication with Insecure Communication. Comet ACM, 1981,24(11):770-773

4. CHANG C C, WU T C. Remote Y}ssword Authentication with Smart Cards. iEE Proc E, 1991,138(3):165 } 168

5. CHANCE C C, Laih l' S. Correspondence for Remote Password Authentication with Smart Cards. IEE Proc E, 1992, 139(4):372一375

6. CHANC: C C, Hwang S J. Using Smart Cards to Authenticate Remote asswords. Comput Math Applic, 1993, 26(7):19一27

7. 潭凯军,何晨,诸鸿文.基于矢积的远程Cl令鉴别方案.电子学报,2000,28(2):28-30

文章导航

/