Design and Research of a Dual and Bidirectional Certificateless Identity Authentication Scheme Based on Hybrid SM Series Algorithms
He-Jun Lu, Roben A. Juanatas · 2023
Aiming at security issues such as user password leakage, password cracking, spoofing, replay attack, man-in-the-middle attack, and server-side attack that may occur during the identity authentication process of instant messaging system users, this paper uses a hybrid algorithms of SM2 and SM3 to design a set of a dual and bidirectional certificateless authentication scheme based on SM2, SM3 and random salt value. This solution includes a two-way password authentication security model based on SM2 and SM3+random salt value, and an intelligent secret medium challenge-response two-way authentication security model based on SM2 and SM3 and random salt value. The dual bidirectional security model implemented by using the hybrid SM series algorithms can achieve the full process of ciphertext transmission, storage, and verification during the authentication process, which can effectively prevent the leakage of personal information in the authentication process, and can effectively prevent fraud, man-in-the-middle attacks, password cracking, and account theft during the authentication process.