论文部分内容阅读
FTP协议是一种简单易用的文件传输协议,应用十分广泛,但它以明文形式传输口令和文件,带有与生俱来的不安全性,随着网络的不断发展应用,FTP已成为政府机关和企事业单位传送信息的一种主要手段,以明文形式传输敏感信息,缺乏有效的身份认证以及安全传输机制等这样的隐患将会给国家和企业造成巨大的损失和危害,因此FTP通信系统的安全性研究显得尤为重要。以构建FTP安全通信系统为背景,分析了传统FTP身份认证的缺陷,对比了当前常用的认证技术。在此基础上,提出了一种结合HASH函数、对称密码机制以及挑战/应答机制的基于动态口令的双向认证方案。最后对该方案进行了性能分析。结果表明:该方案具有保护用户身份信息,防止诸如重放、假冒等常见身份认证攻击,实现双向认证的优点。
FTP protocol is a simple and easy to use file transfer protocol, which is widely used. However, it transmits passwords and files in clear text with inherent insecurity. With the continuous development and application of the Internet, FTP has become the government Organs and enterprises and institutions as a means of transmitting information to transmit sensitive information in clear text, the lack of effective authentication and security mechanisms such as transmission of security will cause huge losses and hazards to countries and enterprises, so FTP Communication System The safety study is particularly important. With the background of establishing FTP secure communication system, this paper analyzes the defects of traditional FTP authentication and compares the commonly used authentication technologies. Based on this, a bi-directional authentication scheme based on dynamic password combining HASH function, symmetric cryptography mechanism and challenge / response mechanism is proposed. Finally, the program conducted a performance analysis. The results show that the scheme has the advantages of protecting user identity information, preventing common identity authentication attacks such as replay and counterfeit, and realizing two-way authentication.