首页> 外国专利> METHOD OF DESIGNING PASSWORD BASED AUTHENTICATION AND KEY EXCHANGE PROTOCOL USING ZERO-KNOWLEDGE INTERACTIVE PROOF

METHOD OF DESIGNING PASSWORD BASED AUTHENTICATION AND KEY EXCHANGE PROTOCOL USING ZERO-KNOWLEDGE INTERACTIVE PROOF

机译:基于零知识交互证明的基于密码的认证和密钥交换协议的设计方法

摘要

A protocol designing method that securely performs a password-based authentication and key exchange protocol using a zero-knowledge interactive proof is disclosed. According to this method, various kinds of system parameters required for authentication are first set. Then, a user selects a certain random number in conformity with the set parameters, and sends to a server a message including a user ID, a test number A applying a one-way function, and a first question number generation value X known only to the server and the user. The server, using the message sent from the user, sends to the user a message including an authentication Auth of whether the server possesses a public key, and a second question number generation value Y known only to the server and the user. The user authenticates the server by verifying the authentication Auth, and computes a resultant value c of a secret coin tossing known only to the server and the user and a session key SK. Thereafter, the user sends to the server a witness number B for user authentication. The server that stores a password verifier V for the respective user verifies the witness number B using the value c, and exchanges the session key SK by computing the session key SK. Accordingly, a secure authentication and key exchange can be performed only using the password without the necessity of any tool such as a smart card.
机译:公开了一种协议设计方法,其使用零知识交互证明来安全地执行基于密码的认证和密钥交换协议。根据该方法,首先设置认证所需的各种系统参数。然后,用户根据设置的参数选择某个随机数,并向服务器发送一条消息,该消息包括用户ID,应用单向功能的测试数A和仅已知的第一问题数生成值X服务器和用户。服务器使用从用户发送的消息,向用户发送消息,该消息包括关于服务器是否具有公共密钥的认证Auth,以及仅服务器和用户已知的第二问题编号生成值Y。用户通过验证认证Auth来认证服务器,并计算仅服务器和用户已知的秘密抛硬币的结果值c和会话密钥SK。此后,用户将证人编号B发送到服务器以进行用户身份验证。存储用于各个用户的密码验证器V的服务器使用值c来验证见证人编号B,并且通过计算会话密钥SK来交换会话密钥SK。因此,可以仅使用密码来执行安全认证和密钥交换,而无需诸如智能卡之类的任何工具。

著录项

  • 公开/公告号KR100445574B1

    专利类型

  • 公开/公告日2004-08-25

    原文格式PDF

  • 申请/专利权人

    申请/专利号KR20010081105

  • 发明设计人 양대헌;이석준;정병호;

    申请日2001-12-19

  • 分类号H04L9/32;

  • 国家 KR

  • 入库时间 2022-08-21 22:46:45

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号