论文部分内容阅读
为解决采用基于证书认证方式的网络用户与采用基于身份认证方式的网络用户之间相互认证的问题,利用对称加密、数字签名和消息认证码等技术,首先构造一个认证链路模型下会话密钥安全的认证协议,然后设计消息认证器把该协议转换成非认证链路模型下的会话密钥安全的认证协议,并对该协议的安全性进行了分析.分析表明,该协议实现了不同认证方式的信任域中用户间的认证、密钥协商以及密钥更新,并在Canetti-Krawczyk(CK)模型下满足安全属性需求.此外,该协议仅需4次通信即可完成,且扩展性好,为不同认证机制的网络用户间认证提供了一种较为实用的解决方案.
In order to solve the problem of mutual authentication between network users based on certificate authentication and network users adopting identity-based authentication, using the technology of symmetric encryption, digital signature and message authentication code, the session key of a certified link model Secure authentication protocol, and then design the message authenticator to convert the protocol into session key-safe authentication protocol under the non-certified link model and analyze the security of the protocol.The analysis shows that the protocol implements different authentication Authentication, key agreement and key renewal among users in the trust mode, and meet the requirements of security attributes under the Canetti-Krawczyk (CK) model.In addition, the protocol can be completed in only four communications and is scalable , Provides a more practical solution for the authentication of network users with different authentication mechanisms.