论文部分内容阅读
本文首先对典型的S/KEY口令序列认证方案的基本原理、实现方式进行了简单说明,通过研究该认证方案的工作过程和分析其安全性,指出其认证方案中所存在的安全缺陷。在综合S/KEY口令序列认证方案和SAS-2认证方案的基础上,本文提出了一种新型的一次性口令认证方案——NOTP(NewOne-TimePassword)认证方案。NOTP认证方案具有认证步骤简单、执行性能优异、无需重新初始化等特点。同时,NOTP认证方案还增强了抵御各种针对一次性口令认证方案攻击的能力,安全性得到了提高。
In this paper, the basic principle and implementation of a typical S / KEY password sequence authentication scheme are briefly described. The working process of the authentication scheme is analyzed and its security is analyzed. The security flaws in the authentication scheme are pointed out. Based on the S / KEY password sequence authentication scheme and SAS-2 authentication scheme, this paper presents a new one-time password authentication scheme --NOTP (NewOne-TimePassword) authentication scheme. NOTP certification program has a certification step is simple, excellent performance, without reinitialization and so on. At the same time, the NOTP certification program also enhances the ability to withstand a variety of attacks against one-time password authentication scheme, security has been improved.