该文在现有身份认证技术的基础上,基于一次性口令(OTP)认证技术,提出了移动商务环境下的一种身份认证方案。与传统方案相比,该方案考虑了移动商务的安全性要求及移动设备的技术限制,引入服务提供次数作为不确定因素,安全性高,运算量小,实现了通信双方的相互认证。
This paper proposes a new OTP authentication scheme based on One-time password and adapt it into M-commerce environment. Compared to traditional schemes, the scheme considers the strains of wireless network and mobile equipment. The scheme not only could isolate such problems of traditional schemes, but also could provide mutual authentication between the user and the server.