To solve the problem of end-to-end encipherment in smart-phone mobile access
an improved two-phase handshaking SSL protocol based on SWIM card public-key authentication is proposed. It accomplishes identity authentication and shared-key agreement between mobile telephone and gateway in the first phase. Then
the information produced in the forepart is used to replace the certification part of standard SSL handshaking protocols in the second phase. The shared-key and random number created in the first phase are used to produce session key and initialization vector for the encryption communication between mobile telephone and gateway by creating standard SSL keys. The security of improved two-phase handshaking SSL protocol is proved by BAN-logic reasoning
and the improved protocol is more adaptive for security needs of mobile applications than WAP protocols in four aspects: end-to-end security
efficient bandwidth change
the key calculation intensity and the universality of mobile terminal. In the same experiment environment
the time for a security connection established between mobile telephone and gateway is shortened from 3.5 s to 1.5 s.
关键词
Keywords
references
徐永强. 基于SSL的安全数据通道的理论与实践 [J].电子科技,2004(6):40-42.
Xu Yongqiang. The theory and practice of the SSL based safe data channel [J]. Electron Science and Technology, 2004(6):40-42.
樊时凯,王敏. SSL通信的中间人攻击与防范 [J]. 信息网络安全,2004(9):57-58.
Fan Shikai, Wang Min. The man in the middle attack in SSL communication [J]. Netinfo Security, 2004(9):57-58.
Meadows C. Analysis of the Internet key exchange protocol using the NRL protocol analyzer [C]∥Proceedings of the IEEE Symposium on Security and Privacy. Los Alamitos, USA: IEEE Computer Society, 1999: 84-89.