计算机与现代化 ›› 2025, Vol. 0 ›› Issue (01): 120-126.doi: 10.3969/j.issn.1006-2475.2025.01.019

• 算法设计与分析 • 上一篇    

无连接场景下基于国密算法的身份认证方法







  

  1. (西安石油大学计算机学院,陕西 西安 710065)
  • 出版日期:2025-01-27 发布日期:2025-01-27
  • 基金资助:
    2018教育部产学合作协同育人项目(201802224022); 陕西省学位与研究生教育研究项目(SXGERC2023085)

Identity Authentication Scheme Based on National Cryptographic Algorithm in No Connection

  1. (Institute of Computer Science, Xi’an Shiyou University, Xi’an 710065, China)
  • Online:2025-01-27 Published:2025-01-27

摘要: 传统身份认证方案中,口令、令牌、生物特征等认证方式大多要求用户必须在与服务器端有电磁连接的情况下进行认证,存在着认证信息被截获和攻击的安全风险。为此,本文设计一种无连接状态下基于国密算法的身份认证方案。方案通过二维码和国密算法的配合,在认证方与用户无连接的状态下,形成一个完整的闭环流程来验证用户身份。相较于传统身份认证方案,本文提出的无连接认证方式能有效避免受到潜在电磁攻击的危险,方案原理简单,具有安全性更高、投资更小的特点,在非接触门禁、信息系统登录验证等场景中具有较大的实用作用。

关键词: 无连接, 身份认证, 国密算法, 二维码, 避免电磁攻击

Abstract:  In traditional identity authentication schemes, methods such as passwords, tokens and biometric features often require users to authenticate themselves while having an electromagnetic connection with the server. These pose security risks of authentication information being intercepted and attacked. Therefore, the article designs an identity authentication scheme based on national cryptographic algorithm in no connection. Through the coordination of QR codes and national cryptographic algorithm, the scheme forms a complete closed-loop process to verify the user’s identity in the state of no connection between the authenticator and the user. Compared with traditional identity authentication schemes, the connectionless authentication scheme proposed in this paper can effectively avoid the danger of potential electromagnetic attacks. The scheme has the characteristics of simple principle, higher security and less investment, which is practiceable in non-contact access control, information system login verification and other scenarios.

Key words: no connection, identity authentication, national cryptographic algorithm, QR codes, avoiding electromagnetic attack

中图分类号: