抗抵赖性是手机支付安全协议的关键特性。扩展Lamport哈希链鉴权协议,并结合SIM卡安全特性,利用对称密码算法和哈希函数实现证据保全功能,设计了一种集鉴权、消息完整性、消息机密性、防重传攻击等功能于一体的、高效实用的手机支付鉴权协议。论述了研究基础,详细阐述了协议的内容;在分析协议安全性的过程中重点剖析抗抵赖性和数据完整性,简要分析了协议性能。分析表明,该协议的安全性和性能都得到了大大提高。
Non-repudiation is the key property of security protocols for the mobile payment.This paper designed an efficient and practical mobile payment authentication protocol of non-repudiation by extending the Lamport's hash chain authentication protocol,which was combined with security features of SIM card for mobile phone,implementing preserved evidence problems for mobile payment by symmetric algorithms and hash functions.Functions of authentication,integrity,confidentiality,and preventing relay attacks were integrated in the protocol.This paper introduced research background and related works,then described the contents of the protocol in detail.Furthermore,emphasized non-repudiation and integrity in the process of analyzing the protocol's security,also presented the performance of the protocol.Analysis show that the security and performance of the protocol have been improved greatly,compared to that of the mobile payment protocol which is realized by the support of the public key cryptography algorithm.