计算机应用 ›› 2009, Vol. 29 ›› Issue (11): 2936-2938.

• 信息与网络安全 • 上一篇    下一篇

基于公钥体制的3GPP认证与密钥协商协议

邓亚平1,付红2,谢显中3,张玉成4,石晶林4   

  1. 1. 重庆邮电大学计算机学院
    2. 重庆邮电大学
    3. 重庆邮电大学 计算机科学与技术学院
    4. 中国科学院 计算技术研究所
  • 收稿日期:2009-05-18 修回日期:2009-07-12 出版日期:2009-11-01 发布日期:2009-11-26
  • 通讯作者: 付红
  • 基金资助:
    国家自然科学基金资助项目

3GPP authentication and key agreement protocol based on public key cryptosystem

Ya-ping DENG,Hong FU,Xian-zhong XIE,Yu-cheng ZHANG,Jing-lin SHI   

  • Received:2009-05-18 Revised:2009-07-12 Online:2009-11-01 Published:2009-11-26
  • Contact: Hong FU

摘要: 对比了第三代移动通信系统中的认证与密钥协商协议,分析了第三代合作伙伴计划(3GPP)最新发布的系统架构演进(SAE) Re1ease 8标准的认证与密钥协商协议,指出了协议中存在的几个安全缺陷。针对协议的安全缺陷,结合公钥密码体制提出一种改进的3GPP SAE认证与密钥协商协议。改进协议利用公钥加密机制保护用户身份信息和网络域的用户认证向量,采用动态随机数方式生成本地认证中需要的密钥。对改进协议进行安全和效率分析的结果表明,该协议可以有效解决上述安全缺陷,能以较少的资源开销获取安全性能的提升。

关键词: 协议安全, 公钥, 认证, 密钥协商, 协议分析

Abstract: The authentication and key agreement protocol adopted by 3rd Generation Partnership Project (3GPP) System Architecture Evolution (SAE) Release 8 standard was analyzed in contrast with 3G, and several security defects in SAE protocol were pointed out, then an improved 3GPP SAE authentication and key agreement protocol was put forward based on public key cryptosystem. In the new protocol, user’s identity information and authentication vector in network domain were encrypted based on public key cryptosystem, public parent key adopted in local authentication was generated by random data. The security and efficiency of the proposed new scheme was analyzed at last. The analysis results show that the proposal can effectively solve the problems mentioned above and improve the security of protocol with less cost.

Key words: protocol security, public key, authentication, key agreement, protocol analysis