移动商务的身份认证问题已成为制约移动商务发展的瓶颈.一次性口令(OTP)技术实现简单、成本低、无须第三方认证的特点使其较适合移动商务的身份认证.利用椭圆曲线密码体制实现数字签名。提出一套基于OTP的移动商务身份认证机制,最后利用BAN逻辑方法证明了该机制的安全性.
The problem of identity authentication has greatly limited development of mobile commerce. The One-Time Password (OTP) technology which is implemented simply, has low cost and needs no third authentication is more suitable for identity authentication in mobile commerce. In this paper, realizing signature through elliptic curve cryptography (ECC) mechanism, the identity authentication mechanism is designed on basis of OTP, and is validated security through BAN logic.