• 中国计算机学会会刊
  • 中国科技核心期刊
  • 中文核心期刊

J4 ›› 2007, Vol. 29 ›› Issue (5): 56-59.

• 论文 • 上一篇    下一篇

一种基于USB Key的双因子身份认证与密钥交换协议

吴永英 邓路 肖道举 陈晓苏   

  • 出版日期:2007-05-01 发布日期:2010-06-02

  • Online:2007-05-01 Published:2010-06-02

摘要:

传统的USB Key只能存储数据而无法进行复杂的加/解密运算,导致基于USB Key的认证协议存在诸多不足。本文针对含智能卡芯片的USB Key可进行加/解密运算和生成随机密钥的特点,提出了一种基于USB Key的双因子身份认证与密钥交换协议DKAKEP。该协议综合运用伪随机数验证、一次性会话密钥、AES加密算法、安全哈希算法等技术,除了可提供安全快速的身份认证与密钥交换,还具有快速更改密钥、支持多种哈希算法和无需时间同步机制的特点。 多种协议攻击,具有较强的实用性、安全性和可靠性。

关键词: 双因子密钥 身份认证 密钥交换 密钥猜测攻击 重放攻击 中间人攻击

Abstract:

Authentication protocols based on traditional USB Key are unable to process complex encryption/decryption data and lead to many disadvantages. Based o n the features that USB Key with a smartcard chip can process complex encryption/decryption and generate random keys, this paper presents a dual key aut hentication and key exchange protocol (DKAKEP). DKAKEP integrates the random number authentication, the one-time session key, the AES encryption and t  the secure hash algorithm, provides secure and fast authentication and key exchange, and supports many useful features such as fast key change, supporti ng multiple hash algorithms and needing no time synchronous mechanisms. The security analysis and practical application indicate that DKAKEP provides go od practicality, security and reliability.

Key words: (dual key, authentication protocol;key exchange, password guessing attack, replay attack; , man in middle attack)