可证明安全的随机密钥协商协议
2017-07-08张小梅吴福生彭长根
张小梅+吴福生+彭长根



摘 要: 主要研究随机密钥协商问题,针对Diffie?Hellman协议、SAKA协议和改进Lin协议、E?SAKA协议等存在的不具有认证功能和不能抵抗中间人攻击等缺陷,应用动态双向认证因子认证方法和非时间同步技术提出一种随机密钥协商协议,该协议适用于OTP动态口令系统设计,同时解决密钥协商过程中的动态认证和时间同步问题。最后,在标准模型下证明了方案的安全性。
关键词: 随机密钥协商; Diffie?Hellman密钥协商; DDH问题; 可证明安全
中图分类号: TN918?34; TP309 文献标识码: A 文章编号: 1004?373X(2017)13?0087?04
Abstract: The random key agreement issue is studied. Since the Diffie?Hellman protocol, SAKA protocol, improved Lin protocol and E?SAKA protocol don′t have the authentication function, and can′t resist the man?in?the?middle attack, a random key agreement protocol is proposed on the basis of the factor authentication method of dynamic bidirectional authentication and non?time synchronization technology, which is suitable for the design of OTP dynamic password system, and can solve the problems of dynamic authentication and time synchronization in the key agreement process. The security of the proposed scheme is proved with the standard model.
Keywords: random key agreement; Diffie?Hellman key agreement; DDH problem; provable security
0 引 言
密钥协商协议是通信双方建立安全会话链接的主要工具之一,能有效保障通信参与方间的安全通信。早在1976年,Diffie和Hellman在“密码学的新方向”一文中提出的公玥密码思想为密钥协商提供了新的解决途径[1]。后续有大量学者在密钥协商方面做了重要的工作[2?4]。文献[4]在标准模型下提出了一种可证明安全的基于身份的认证密钥协商协议;最近,文献[5]提出一种面向无线传感器网络的双因子用户认证协议。可见,密钥协商协议一如既往地受到广大研究人员的重视。
Diffie?Hellman[1]算法是一个著名的双方生成共享密钥的经典协议算法,但是该协议不具有认证功能,不能抵抗中间人攻击。针对Diffie?Hellman协议的不足,文献[2]提出简单密钥交换协议(SAKA),但其存在如下三个缺陷:攻击者虽然不能获得会话密钥,但是可以模仿Bob与Alice建立连接;协议不能抵抗密钥猜测攻击; 协议不能保证前向的安全性。另外一些学者还提出了针对SAKA协议的一些改进协议,如文献[6?9]。……
