信息安全研究 ›› 2019, Vol. 5 ›› Issue (6): 500-506.

• 学术论文 • 上一篇    下一篇

一种基于USB Key的双私钥安全因子身份认证方案

齐锋1,陈庄2,蔡定雯2,于溯2   

  1. 1. 重庆理工大学计算机科学与工程学院
    2. 重庆理工大学
  • 收稿日期:2019-06-03 出版日期:2019-06-15 发布日期:2019-06-03
  • 通讯作者: 齐锋
  • 作者简介:齐锋,硕士研究生,主要研究方向为信息安全、应用密码学. 15123376065@163.com 陈庄,教授、硕士生导师,主要研究方向为企业信息化管理、网络与信息安全. cz@cqut.edu.cn 蔡定雯,硕士研究生,主要研究方向为网络与信息安全、密码学. 842493415@qq.com 于溯,硕士研究生,主要研究方向为信息安全、密码学. 908656918@qq.com

A Dual Private Key Security Factor Identity Scheme Based on USB Key

  • Received:2019-06-03 Online:2019-06-15 Published:2019-06-03

摘要: 针对现有信息系统面临的用户身份认证问题,提出了一种基于USB Key的双私钥安全因子身份认证方案.该方案是基于国产密码算法SM2和SM3共同实现的,首先采用了“用户口令+数字签名”的双重认证方式,且用户口令参与了整个签名过程;其次,引入安全因子的概念,提升了系统受攻击下的认证效率;最后,改进了原有的签名流程,实现了客户端和服务器的双向认证.通过实验验证了方案的正确性和安全性,同时也说明了方案能够满足信息系统身份认证的安全需求,具有一定的实际应用价值.

关键词: SM2, SM3, 信息安全, 身份认证, 数字签名

Abstract: Aiming at the problem of user identity security authentication faced by existing information system, we proposed a dual private key security factor authentication scheme based on USB Key. The scheme is based on the domestic cryptographic algorithm SM2 and SM3. Firstly, the paper adopted “user password+digital signature” double authentication method, and user password participates in the entire signature process. Secondly, the paper introduced the concept of security factor to improve the authentication efficiency under attack. Finally, the paper improved original signature process and realized the mutual authentication between the client and the server. Through experiments, we verified the correctness and security of the scheme, and also showed that the scheme can satisfy the security requirements of identity authentication of information systems and has certain practical application value.

Key words: SM2, SM3, information security, identity authentication, digital signature