为适应密码技术在无线通信中的应用要求,Aydos、Mangipudi等人以椭圆曲线密码为基础,分别提出了适用于无线通信网络的身份认证和密钥交换协议。而研究发现,这些协议中仍存在中间人攻击、服务后否认、假冒攻击等安全隐患,且不能提供前向保密性。为此,本文提出一个安全的身份认证和密钥交换协议,经验证说明该协议不仅能防止上述安全隐患,而且执行效率更好,适于为无线通信环境中用户端与服务器间进行相互认证,建立一个双方共享的会话密钥。
Aydos et al. and Mangipudi et al. proposed an ECC-based wireless authentication and key agreement protocol respectively. Unfortunately, there are some security flaw such as man-in-middle attack, denial-of-service attack, impersonation attack etc. to thse protocols. For this reason, a security enhanced protocol is proposed in this paper, which can not only achieve the essential security achievements of a good MAKAP, but overcome weaknesses referred above. At the end of the protocol, identifies both of parters are testified and they agree a session key for subsequent communication between user and server.