针对当前无线射频识别系统认证过程复杂、安全性差等缺陷,提出一种基于Hash函数与椭圆曲线密码相融合的双向认证方案,以提高无线射频识别系统通信的安全性.首先采用椭圆曲线密码对无线射频识别系统的阅读器进行身份认证;然后采用轻量级Hash函数对无线射频识别系统的标签身份进行认证与验证,大幅度减少公钥与密钥长度,降低计算开销;最后对该方案的可行性进行测试.测试结果表明,相对于其他双向认证方案,该方案能有效抵抗各种类型的攻击,安全性较高,同时降低了内存与通信的开销.
Aiming at the defects of the current radio frequency identification system,such as the complexity of the authentication process,poor security and so on, we proposed a mutualauthentication scheme based on Hash function and elliptic curve cryptography,which improved the security of radio frequency identification system.Firstly,elliptic curve cryptography was used to authenticate the reader of radio frequency identification system.Secondly,lightweight Hash function was used to authenticate and verify the identity of radio frequency identification system,the length of public key and key could be reduced greatly,and computation overhead could be reduced.Finally,the feasibility of the scheme was tested by experiment.Test results show that compared with other mutual-authentication schemes,the proposed scheme can effectively resist all kinds of attacks,and the security is high,at the same time,it reduces the memory and communication overhead.