首页 | 本学科首页   官方微博 | 高级检索  
     

一种适用于HOTP的一次口令生成算法
引用本文:刘建伟,李晖,马建峰.一种适用于HOTP的一次口令生成算法[J].西安电子科技大学学报,2006,33(4):650-654.
作者姓名:刘建伟  李晖  马建峰
作者单位:[1]北京航空航天大学电子信息工程学院,北京100083 [2]西安电子科技大学计算机网络与信息安全教育部重点实验室,陕西西安710071 [3]西安电子科技大学计算机学院,陕西西安710071
摘    要:采用HMAC SHA-1杂凑函数和动态截短函数设计了一次性口令算法HOTPC.该算法具有计算速度快、安全性高的特点,易于采用令牌或IC卡硬件实现.因此.该算法适用于HTOP认证架构.此外.提出了基于令牌的认证协议应具备的3个基本条件.并设计了一种基于计数器同步的认证协议.该协议通过在服务器端设置最大认证尝试次数来防止蛮力攻击.并设置前顾参数来实现计数器重同步.分析表明.谈协议能够有效抵抗蛮力攻击和截获/重放消息等常见攻击.具有很高的安全性.

关 键 词:一次性口令  杂凑函数  认证协议
文章编号:1001-2400(2006)04-0650-05
收稿时间:2005-12-30
修稿时间:2005-12-30

A one time password generation algorithm suitable for HOTP
LIU Jian-wei,LI Hui,MA Jian-feng.A one time password generation algorithm suitable for HOTP[J].Journal of Xidian University,2006,33(4):650-654.
Authors:LIU Jian-wei  LI Hui  MA Jian-feng
Affiliation:(1) School of Electronics and Information Engineering, BeiHang Univ., Beijing 100083, China;(2) Ministry of Edu. Key Lab. of Computer Networks and Information Security, , Xidian Univ., Xi′an 710071, China;(3) School of Computer Engineering, Xidian Univ., Xi′an 710071, China
Abstract:A one time password algorithm HTOP.C is proposed based on HMAC SHA-1 and a dynamic truncating function. The algorithm has a fast computing speed and high security, and it is easy to implement by using Token or IC card hardware. Therefore, the algorithm is suitable for the HTOP authentication framework. Besides, three basic conditions are proposed for the token-based authentication protocol, and an authentication protocol based on counter synchronization is designed. At the server side, the protocol sets up a maximum trying number to prevent the brute-force attack, and a look-ahead parameter to realize counter resynchronization. Finally, the security of the protocol is analyzed. Results show that the protocol can resist normal attacks, such as brute-force attack and interception/replay attack effectively, and is highly secure.
Keywords:one time password  hash function  authentication protocol
本文献已被 CNKI 维普 万方数据 等数据库收录!
点击此处可从《西安电子科技大学学报》浏览原始摘要信息
点击此处可从《西安电子科技大学学报》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号