论文部分内容阅读
在移动商务环境下为了解决全自动区分计算机和人类的公开图灵测试(CAPTCHA)技术易被攻击而失效的问题,提出了适用于该环境的口令认证密钥交换协议.将认证密钥交换过程与CAPTCHA挑战/应答过程巧妙融合,在不增加协议通信轮数的条件下,通过对称加密方案保护CAPTCHA问题实例;采用适于移动终端的椭圆曲线公钥系统,基于智能卡的安全特性,提高了协议的效率和安全性;在随机预言机模型下,给出了安全性证明.与同类协议相比,新协议仅需3轮通信就能使CAPTCHA问题实例免受攻击,无须存储口令验证表,具备前向安全性.
In order to solve the problem that the public Turing Test (CAPTCHA) technology that distinguishes computers and human beings from being easily attacked in the mobile commerce environment, a password authentication key exchange protocol suitable for this environment is proposed. The authentication key exchange process And CAPTCHA challenge / response process clever fusion, without increasing the number of rounds of protocol communications, symmetric encryption scheme to protect the instance of CAPTCHA problems; using mobile terminal elliptic curve public key system, based on the smart card security features to improve the protocol The security and safety of the CAPTCHA problem are given under the random oracle model.Compared with similar protocols, the new protocol can only provide CAPTCHA problem instances with no need to store the password verification table with only three rounds of communication, Forward security.