1. 西安交通大学电子商务研究所,西安,710049
2. 信息工程大学电子技术学院,郑州,450004
网络首发:2007-06-10,
纸质出版:2007
移动端阅览
常朝稳 1, 2, 覃征 1, 等. 基于SWIM卡公钥认证的二阶段握手加密套接层协议[J]. 西安交通大学学报, 2007,41(6):669-673.
常朝稳 1, 2, 覃征 1, et al. Protocol of Two-Phase Handshaking Security Socket Layer Based on SWIM Card Public-Key Authentication[J]. 2007, 41(6): 669-673.
根据普通智能手机移动接入时端端加密的安全需求
提出了一个基于SWIM卡公钥认证的二阶段握手加密套接层(SSL)改进协议.在握手的第1阶段
该协议由SWIM卡完成终端与网关之间基于公钥证书的身份认证
并产生、分发密钥材料.利用第1阶段的认证结果替代标准SSL握手协议的认证部分
利用第1阶段产生的共享密钥、随机数按照标准SSL密钥生成方法生成移动通信双方的会话密钥、初始化向量
进而完成第2阶段的握手SSL改进协议.所提协议的安全性通过了BAN的逻辑推理、证明
其适用性分析结果表明
在端端安全性、通信带宽效率变化、密码运算量和移动终端普适性等方面
它要比无线应用协议更适于移动应用的安全性需要
在相同的实验环境下
移动终端安全接入的时间也从3.5 s缩短到1.5 s.
To solve the problem of end-to-end encipherment in smart-phone mobile access
an improved two-phase handshaking SSL protocol based on SWIM card public-key authentication is proposed. It accomplishes identity authentication and shared-key agreement between mobile telephone and gateway in the first phase. Then
the information produced in the forepart is used to replace the certification part of standard SSL handshaking protocols in the second phase. The shared-key and random number created in the first phase are used to produce session key and initialization vector for the encryption communication between mobile telephone and gateway by creating standard SSL keys. The security of improved two-phase handshaking SSL protocol is proved by BAN-logic reasoning
and the improved protocol is more adaptive for security needs of mobile applications than WAP protocols in four aspects: end-to-end security
efficient bandwidth change
the key calculation intensity and the universality of mobile terminal. In the same experiment environment
the time for a security connection established between mobile telephone and gateway is shortened from 3.5 s to 1.5 s.
徐永强. 基于SSL的安全数据通道的理论与实践 [J].电子科技,2004(6):40-42.
Xu Yongqiang. The theory and practice of the SSL based safe data channel [J]. Electron Science and Technology, 2004(6):40-42.
樊时凯,王敏. SSL通信的中间人攻击与防范 [J]. 信息网络安全,2004(9):57-58.
Fan Shikai, Wang Min. The man in the middle attack in SSL communication [J]. Netinfo Security, 2004(9):57-58.
WAP Forum. Wireless application protocol architecture specification [EB/OL].(1998-04-30)[2006-01-01]. http:∥www.wapforumorg/wap.
钱勇. 认证协议设计与分析方法的研究 [D]. 上海: 上海交通大学计算机科学与技术系, 2001.
Meadows C. Analysis of the Internet key exchange protocol using the NRL protocol analyzer [C]∥Proceedings of the IEEE Symposium on Security and Privacy. Los Alamitos, USA: IEEE Computer Society, 1999: 84-89.
0
浏览量
5
下载量
0
CSCD
关联资源
相关文章
相关作者
相关机构
京公网安备11010802024621