码迷,mamicode.com
首页 > 其他好文 > 详细

Challenge–response authentication

时间:2017-12-26 19:06:56      阅读:132      评论:0      收藏:0      [点我收藏+]

标签:any   response   must   安全   常用   multi   https   with   bsp   

In computer securitychallenge–response authentication is a family of protocols in which one party presents a question ("challenge") and another party must provide a valid answer ("response") to be authenticated.

The simplest example of a challenge–response protocol is password authentication, where the challenge is asking for the password and the valid response is the correct password.

 

Clearly an adversary who can eavesdrop on a password authentication can then authenticate itself in the same way. One solution is to issue multiple passwords, each of them marked with an identifier. The verifier can ask for any of the passwords, and the prover must have that correct password for that identifier. Assuming that the passwords are chosen independently, an adversary who intercepts one challenge–response message pair has no clues to help with a different challenge at a different time.

 

通常用于安全级别较高的找回密码等功能。比如qq、微信等,需要提供多重验证。

 

基于会话的安全认证机制:

A 老姑,我要和你借20元钱;

B 你是?

A 我是XX的儿子;

B 你的伯父叫什么?姑姑叫什么?你爸兄妹几个?

A 哔哩哔哩.....

B 你爷爷叫什么?

A bilibili

B 50元够不够?

A 够了;谢谢!

Challenge–response authentication

标签:any   response   must   安全   常用   multi   https   with   bsp   

原文地址:https://www.cnblogs.com/feng9exe/p/8119435.html

(0)
(0)
   
举报
评论 一句话评论(0
登录后才能评论!
© 2014 mamicode.com 版权所有  联系我们:gaon5@hotmail.com
迷上了代码!