标题: | 使用通行码的数位签章协定 Password-based Signature Scheme |
作者: | 李尚宸 曾文贵 资讯科学与工程研究所 |
关键字: | 通行码验证;数位签章;抵挡字典攻击法;Password-based authentication;Signature scheme;Against dictionary attack |
公开日期: | 2003 |
摘要: | 我们知道使用通行码的协定必须能抵抗字典攻击法,因此我们提出一个必须结合服务者的秘密资讯、客户所知道的秘密资讯及通行码才能产生合法的数位签章的协定。因为协定的需求是正确的客户及服务者才能产生合法的数位签章,所以我们必须要确认客户以及服务者的身份。完成了身份认证的要求后所产生的数位签章可以利用相对应的公开金钥来验证其合法性。在客户的秘密资讯泄漏,或是服务者的秘密资讯泄漏的情况下,攻击者皆无法利用字典攻击法得知通行码或是伪造出一个合法的数位签章。另外我们也对我们的协定给予一个安全性的证明。 We know that password-based schemes must be able to against dictionary attacks. We proposed a digital signature scheme that we have to know the password, client and server’s secret to sign out a valid signature. Because we require that the valid signature could only be produced if both client and server are correct, client and server need to authenticate each other. We can verify the signature which is produced after authentication by the corresponding public keys. If the secret either server or client holds has been leaked out, the attacker can not neither find out the correct password nor forge a valid signature by using dictionary attacks. And there is also a security proof for our signature scheme. |
URI: | http://140.113.39.130/cdrfb3/record/nctu/#GT009123586 http://hdl.handle.net/11536/53423 |
显示于类别: | Thesis |
文件中的档案:
If it is a zip file, please download the file and unzip it, then open index.html in a browser to view the full text content.