首页|基于SM9的可指定验证双向身份认证方案

基于SM9的可指定验证双向身份认证方案

Abidirectional authentication scheme with designated verifier based on SM9

扫码查看
针对身份认证过程中数字签名泄露双方身份信息的问题,提出一种基于SM9的可指定验证双向身份认证方案.该方案基于应答式双向身份认证模型,在身份认证阶段将对方生成的随机群元素代入数字签名的生成过程,在密钥协商阶段为问候消息添加时间戳使会话密钥拥有时效性.理论分析结果表明,该方案在保护认证双方身份信息隐私的同时,能够有效防止攻击者对会话密钥进行重放攻击.与其他方案相比,该方案提供了更高安全性且具有较好的性能.
In order to solve the problem of digital signatures leaking identity information from both parties during the identity authentication process,a bidirectional identity authentication scheme with designated verifier based on SM9 is proposed.This scheme is based on a responsive bidirectional i-dentity authentication model,which incorporates random group elements generated by the other par-ty into the process of generating digital signatures during the identity authentication stage.At the same time,adding a timestamp to the greeting message during the key agreement phase,to make the session key timeliness.Theoretical analysis results indicate that this scheme can effectively prevents attackers from performing replay attacks on session keys while protecting the privacy of identity in-formation of both authentication parties.Compared with other schemes,this scheme has good effi-ciency while providing higher security.

SM9 algorithmdigital signaturebidirectional authenticationdesignated verifierkey a-greement

张雪锋、郭奥磊、程叶霞

展开 >

西安邮电大学 网络空间安全学院,陕西 西安 710121

中国移动通信有限公司研究院,北京 100053

SM9算法 数字签名 双向身份认证 指定验证者 密钥协商

陕西省自然科学基础研究计划项目

2022JQ-600

2024

西安邮电大学学报
西安邮电学院

西安邮电大学学报

CSTPCD
影响因子:0.795
ISSN:1007-3264
年,卷(期):2024.29(4)