为增加密钥协商协议的安全性,提高会话密钥协商的效率,提出一种双实体单向可认证的密钥协商方案。在该方案中,协议发送方首先向接收方发送一个无证书数字签名,签名中包含发送方公钥、标识号、时间戳等能鉴别身份的信息;然后,接收方验证数字签名的有效性,并利用Diffie—Hellman密钥交换协议与发送方建立会话密钥。该方案不仅在随机预言模型下可证明是安全的,而且也同时满足会话密钥安全性、前向安全性、会话密钥的不可控性和抗密钥泄露伪造攻击等安全属性。
In order to improve the security and efficiency of the key agreement protocol, a secure one-pass and two-party authenticated key agreement protocol is proposed. In this protocol,a certificateless digital signature is sent to the receiver,in which the sender's public key,identification number,time stamp, and other identifiable information are signed. Then, the receiver verifies the variety of the digital signature. The session key is built by using the Diffie-Hellman key agreement protocol. The new protocol can be proved to be secure in random ora- cle model;it can also satisfy the properties of known session key secrecy, forward secrecy,uncontrollability of the session key and key compromise impersonation resilience.