首页 | 本学科首页   官方微博 | 高级检索  
     

会话初始协议安全认证机制的分析与改进
引用本文:赵跃华,刘申君.会话初始协议安全认证机制的分析与改进[J].计算机工程,2011,37(20):114-116.
作者姓名:赵跃华  刘申君
作者单位:江苏大学计算机科学与通信工程学院,江苏镇江,212013
摘    要:通过分析会话初始协议相关认证机制,指出认证中可能存在的安全威胁,如离线密钥猜测攻击和Denning-Sacco攻击。针对安全漏洞提出一种结合椭圆曲线密码的改进认证机制。安全性分析表明,改进的认证机制在提供客户端和服务器间双向认证的同时,能够完成会话密钥传递,确保认证的时效性,有效抵御离线密钥猜测攻击和Denning-Sacco攻击。

关 键 词:会话初始协议  认证  安全性  椭圆曲线密码  椭圆曲线离散对数问题
收稿时间:2011-03-10

Analysis and Improvement of Secure Authentication Mechanism for Session Initiation Protocol
ZHAO Yue-hua,LIU Shen-jun.Analysis and Improvement of Secure Authentication Mechanism for Session Initiation Protocol[J].Computer Engineering,2011,37(20):114-116.
Authors:ZHAO Yue-hua  LIU Shen-jun
Affiliation:(School of Computer Science & Telecommunications Engineering,Jiangsu University,Zhenjiang 212013,China)
Abstract:Through analyzing the Session Initiation Protocol(SIP) authentication mechanism,this paper describes the vulnerability and possible attacks,such as off-line password guessing attacks and Denning-Sacco attacks.Aiming at such security problems,an improved SIP authentication scheme based on Elliptic Curve Cryptography(ECC) is proposed.Security analysis demonstrates that the improved scheme can provide mutual authentication,share the session key,guarantee the validity of authentication,effectively resist against off-line password guessing attacks and Denning-Sacco attacks.
Keywords:Session Initiation Protocol(SIP)  authentication  security  Elliptic Curve Cryptography(ECC)  Elliptic Curve Discrete Logarithm Problem(ECDLP)
本文献已被 CNKI 维普 万方数据 等数据库收录!
点击此处可从《计算机工程》浏览原始摘要信息
点击此处可从《计算机工程》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号