电信科学 ›› 2017, Vol. 33 ›› Issue (8): 163-172.doi: 10.11959/j.issn.1000-0801.2017178

• 运营技术广角 • 上一篇    下一篇

一种适用于NFC移动设备的双向认证安全方案

张呈钰1,王让定1,姚灵2,傅松寅1,左富强2   

  1. 1 宁波大学信息科学与工程学院,浙江 宁波 315211
    2 宁波水表股份有限公司,浙江 宁波 315032
  • 修回日期:2017-06-04 出版日期:2017-08-01 发布日期:2017-08-25
  • 作者简介:张呈钰(1992-),女,宁波大学信息科学与工程学院硕士生,主要研究方向为NFC应用、智能仪器仪表。|王让定(1962-),男,博士,宁波大学信息科学与工程学院教授、博士生导师,主要研究方向为多媒体通信与取证、信息安全、智能抄表及传感网络技术等。|姚灵(1953-),男,宁波水表股份有限公司技术总监、教授级高级工程师兼任中国计量协会水表工作委员会副秘书长,主要研究方向为流量仪表与精密仪器。|傅松寅(1982-),男,宁波大学信息科学与工程学院博士生、助理研究员,主要研究方向为无线传感网络、智能抄表。|左富强(1982-),男,宁波水表股份有限公司高级工程师,主要研究方向为智能水流量仪表及嵌入式系统。
  • 基金资助:
    国家自然科学基金资助项目(61672302);浙江省重中之重学科资助项目(XKXL1509);宁波市科技局产业技术创新及成果产业化重点资助项目(2013B10034);宁波市智能水表与测控技术科技创新团队项目

A mutual authentication security scheme for mobile NFC devices

Chengyu ZHANG1,Rangding WANG1,Ling YAO2,Songyin FU1,Fuqiang ZUO2   

  1. 1 College of Information Science and Engineering,Ningbo University,Ningbo 315211,China
    2 Ningbo Water Meter Co.,Ltd.,Ningbo 315032,China
  • Revised:2017-06-04 Online:2017-08-01 Published:2017-08-25
  • Supported by:
    The National Natural Science Foundation of China(61672302);The Key Subject Program of Zhejiang Province(XKXL1509);Innovation and Industrialization Key Program of Science Technology Department of Ningbo(2013B10034);Project of Ningbo Intelligent Water Meter and Measurement and Control Technology of Science and Technology Innovation Team

摘要:

近场无线通信(NFC)是一种已经被广泛应用的短距无线通信技术。其中最常见的是将NFC技术应用于移动支付和门禁访问控制等应用。从技术上讲,这些应用利用NFC模拟卡模式将NFC设备模拟成银行卡或门禁卡,然后等待外部阅读器验证。在这类应用场景下,选取合适的安全认证方案是非常重要的。首先,介绍了现有的NFC认证系统和安全方案并分析了系统安全需求和潜在的安全风险。然后,采用Hash、AES和口令Key动态更新机制,提出了一种适用于NFC移动设备的双向认证安全方案,并设计了自同步机制。最后,利用GNY逻辑以形式化证明的形式证明了方案的安全性,分析表明该方案能解决伪造、重放攻击、窃听、篡改、异步攻击等安全问题。

关键词: 近场无线通信, 双向认证, 安全, 移动设备

Abstract:

Near field communication (NFC) is a kind of short-range wireless communication technology which has been applied around the world.The applications of mobile payments and access control are the most common applications of NFC technology.Technically,the NFC device can be used as a bank card or an entrance card with the help of the card emulation mode of NFC,which will be validated by external reader.It is very essential to select a appropriate and safe certification scheme in this scenario.First of all,the existing NFC authentication system and security scheme was introduced and the system security requirements and potential security risks were analyzed.Then,by using Hash,AES and password Key dynamic updating mechanism,a mutual authentication security scheme for mobile NFC devices was proposed,and the synchronization mechanism was designd.Finally,GNY logic was used to prove the security correctness of our proposed scheme.The security analysis shows that our scheme can avoid a number of attacks,such as forgery,replay attack,eavesdropping,tampering attack,asynchronous attack and so on.

Key words: near field communication, mutual authentication, security, mobile device

中图分类号: 

No Suggested Reading articles found!