期刊导航

论文摘要

基于双随机软输入模型的一次性口令认证方法

One-time Password Authentication Based on Double Random Soft Input Model

作者:陈静(西南交通大学CAD工程中心);孙林夫(西南交通大学CAD工程中心)

Author:Chen Jing(CAD Eng. Center,Southwest Jiaotong Univ.);Sun Lin Fu(CAD Eng. Center,Southwest Jiaotong Univ.)

收稿日期:2009-09-27          年卷(期)页码:2010,42(2):154-159

期刊名称:工程科学与技术

Journal Name:Advanced Engineering Sciences

关键字:双随机软输入模型;软输入接口单元;软控制接口单元;软逻辑输入单元;一次性口令;身份鉴别

Key words:double random soft input model; soft input interface unit; soft control interface unit; soft logic input unit; one-time password; authentication

基金项目:国家科技支撑计划(2006BAF01A48);四川省科技计划资助项目(2008GZ0007)

中文摘要

针对现有的一次性口令认证技术在B/S模式下应用的局限性,提出了基于双随机软输入模型的一次性口令认证方法。该方法的核心思想是,当用户需要输入认证口令时,认证服务器动态生成双随机输入软键盘,即每次生成的软键盘的界面接口布局是随机的,且其接口对应的输入字符也是随机的。研究结果表明该方法不需要在客户端进行任何计算,就可保证每次在客户端输入的口令及在网络上传输的认证口令由若干组不同的随机字符串组合而成,有效解决了口令认证中的捕获/重放攻击、内存截获及输入截获攻击问题。

英文摘要

The existing one-time password authentication technology was analyzed. To overcome its limitations on B/S application mode,a soft input model based on double random input unit was put forward. When the user need to input authentication password, the authentication server dynamically generates double random input soft keyboard, the interface layout of soft keyboard generated by the authentication server each time is random, and its interface to the corresponding input character is also random. The study results showed that based on this method, the password entered in client and password transmitted over the network are mapped to several groups of different random string each time without any computing in client, and effectively solves some password authentication problems including the capture/replay attack, memory and input intercepted assault.

关闭

Copyright © 2020四川大学期刊社 版权所有.

地址:成都市一环路南一段24号

邮编:610065