摘要
针对身份认证中可能出现的数字身份被冒用问题,提出了一种强双因子身份认证方案,将生成的数字证书及私钥存储于用户智能卡中,再使用fuzzy vault保护智能卡的PIN。通过组合2种不同条件来证明一个人的身份,安全性有了明显提高。同时为了减轻智能卡的计算负担,引入秘密共享思想,当且仅当用户智能卡和指纹服务器中信息都可得时,才释放其中绑定的智能卡PIN。该方案进一步完善了PKI的安全认证,适用于高端用户或有特殊需要的高安全度客户的身份认证。
A scheme named strong two-factor authentication was proposed,to resolve the possible issues of digital identity illegally used by attackers.We stored the generated digital certificate and its private key in a smartcard and protected the PIN of the smartcard by fuzzy vault.The security was improved obviously through combining two kinds of factors to prove one's identity.Meanwhile in order to relieve the computational burden of the smartcard,we imported secret sharing.Only when both the information of the smartcard and the fingerprint server are acquired,would the binding PIN of the smartcard be released.This scheme further perfects the authentication of PKI and is suitable for the authentication of high-end users or high safety customers with special requirements.
出处
《武汉理工大学学报》
CAS
CSCD
北大核心
2011年第3期161-164,共4页
Journal of Wuhan University of Technology
基金
国家高技术研究发展计划(863计划)(2008AA01Z411
2009AA01Z440)
国家自然科学基金(60803150
60803151)
湖北省自然科学基金重点项目(2008CDA020)
国家自然科学基金委员会-广东联合基金重点项目(U0835004)
关键词
模糊保险箱
数字证书
私钥
身份认证
智能卡
fuzzy vault
digital certificate
private key
identity authentication
smartcard