针对不稳定网络环境下的远程登录管理不能有效进行安全密码认证和密码更新的问题,提出一种对称密钥结合椭圆曲线加密(ellipticcurvecryptography,ECC)的网络认证和密码更新方案。其主要贡献在于弥补现有方案的一些漏洞,并给出改进方案。新方案包含注册、口令认证、密码更新和会话密钥分发四个阶段,提供对密码猜测攻击、服务器欺骗攻击、数据窃听、重放攻击的防御。此外,提出的方案可产生一个通用对称密钥,相比公钥加密技术,所需处理时间更少。实验结果显示,该方案的虚拟计算时间仅为2.00035s,只在17哈希、8异或和4点运算方面需要计算开销。
As the remote login management in unstable netw ork en vironm ent can not effectively secure password au then ticationand password u p d a tin g , this paper proposed netw ork au then tication and password replacem ent program using sym m etric key accelerationand the e llip tic curve cryptography ( E C C ) . The m ain co n trib u tio n was to make up some o f the loopholes in the e x istingprogram s, and gave im provem ents. The new program consisted o f fo u r phases: registration phase, password au then tication phase, password update phase and session key d is trib u tio n ph ase, p ro vid in g defense o f password guessing a tta c k s , serverspoofing a tta cks, data in te rce p tio n attacks and replay attacks. A lso the proposed scheme can produce a common sym m etrick e y , com pared to p u b lic -k e y encryption technology com pared, and the re quire d processing tim e is less. The v irtu a l com putingtim e is 2 .0 0 0 35 seconds, on ly in c lu d in g the cost o f 17 tim es hash, 8 tim es X O R and 4 tim es dot operation in total.