移动商务的身份认证问题已成为制约移动商务发展的瓶颈。一次性口令技术实现简单、成本低、无须第三方认证的特点使其较适合移动商务的身份认证。通过椭圆曲线密码体制实现数字签名和密钥协商,提出基于一次性口令和椭圆曲线密码体制的移动商务身份认证协议,并利用串空间方法证明协议的安全性。
The problem of identity authentication has greatly limited the development of mobile commerce. The One- Time Password technology, which is easy, has low cost and needs no third authentication, is more suitable for identity authentication in mobile commerce. On the basis of verifying signature and key agreement by elliptic curve cryptography mechanism, mobile commerce identity authentication protocol is designed on use One-Time Password via Strand Space method to gain security.