电子与信息学报2024,Vol.46Issue(5) :2137-2148.DOI:10.11999/JEIT231197

支持商密SM9算法框架的多因素认证方案

A Multi-Factor Authentication Scheme Under the SM9 Algorithm Framework

朱留富 汪定
电子与信息学报2024,Vol.46Issue(5) :2137-2148.DOI:10.11999/JEIT231197

支持商密SM9算法框架的多因素认证方案

A Multi-Factor Authentication Scheme Under the SM9 Algorithm Framework

朱留富 1汪定1
扫码查看

作者信息

  • 1. 南开大学网络空间安全学院 天津 300350;天津市网络与数据安全技术重点实验室 天津 300350;数据与智能系统安全教育部重点实验室 天津 300350
  • 折叠

摘要

无线传感器技术使用公开无线信道且存储和计算资源受限,这使其容易遭受潜在的主动攻击(篡改等)和被动攻击(监听等).身份认证是保障信息系统安全的第一道防线,如何为无线传感器设备设计多因素认证方案是目前安全协议研究的热点.目前,大多数身份认证方案都基于国外密码标准设计,不符合国家核心技术自主可控的网络空间安全发展战略.商密SM9标识密码算法是中国密码标准,已由ISO/IEC标准化并被广泛使用.因此,该文研究如何在商密SM9标识密码算法框架下,将口令、生物特征以及智能卡相结合来设计多因素身份认证方案,并利用模糊验证技术和蜜罐口令方法增强口令安全.该文在随机谕言模型(Random Oracle Model,ROM)下证明了方案的安全性,并给出启发式安全分析.与相关身份认证方案的对比结果表明,该文提出的身份认证方案在提供安全性的同时能够适用于资源受限的无线传感器网络.

Abstract

Wireless sensor networks use public wireless channels and their storage and computing resources are limited,making them vulnerable to active attacks and passive attacks.Identity authentication acts as the first line to ensure the security of information systems.Then,how to design multi-factor authentication schemes for wireless sensor devices is currently a hot topic.Nowadays,most existing schemes are based on foreign cryptographic standards that do not comply with the autonomous and controllable cyberspace security development strategy.SM9 is an identity-based cryptographic algorithm that has become a Chinese cryptographic standard recently.Therefore,this paper focuses on how to combine passwords,biometrics,and smart cards to design a multi-factor authentication scheme that can be used for wireless sensor networks under the framework of SM9.The proposed scheme applies the fuzzy verifier technique and the honeyword method to resist password guessing attacks and further enables session key negotiation and password update.The security is proved under the Random Oracle Model(ROM)and a heuristic security analysis is provided additionally.The comparison results show that the proposed scheme can be deployed to wireless sensor networks.

关键词

多因素认证/国产密码/随机谕言模型

Key words

Multi-factor authentication/Chinese cryptographic standard/Random oracle model

引用本文复制引用

基金项目

京津冀基础研究合作专项(21JCZXJC00100)

国家自然科学基金(62222208)

天津市自然科学基金重点项目(21JCZDJC00190)

出版年

2024
电子与信息学报
中国科学院电子学研究所 国家自然科学基金委员会信息科学部

电子与信息学报

CSTPCD北大核心
影响因子:1.302
ISSN:1009-5896
段落导航相关论文