Method for preventing replay attacks to long connection

An anti-replay and long-term connection technology, applied in the field of information security, achieves good effects and wide application range

Active Publication Date: 2016-12-14
INSPUR SOFTWARE CO LTD
View PDF5 Cites 11 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

The disadvantage of this method is that the range of the challenge value and the response value should be wide enough, otherwise the attacker only needs to intercept enough challenge-response relationships to carry out replay attacks

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Method for preventing replay attacks to long connection

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0020] In order to make the technical problems, technical solutions and beneficial effects to be solved by the present invention clearer, the present invention will be described in detail below in conjunction with the accompanying drawings and embodiments. It should be noted that the specific embodiments described here are only used to explain the present invention, not to limit the present invention.

[0021] The long connection anti-replay attack method comprises the following steps:

[0022] (1) The client (1010) initiates a connection to the server (2010), and the server returns a random number to the client (2020);

[0023] (2) The client uses the composite key to perform HMAC calculation on the password used by the client user, obtains the client HMAC calculation result (1030), and sends the user name plaintext and the client HMAC calculation result to the server (1040) ;

[0024] (3) After receiving the HMAC calculation result from the client, the server queries the p...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

PUM

No PUM Login to View More

Abstract

The invention particularly relates to a method for preventing replay attacks to a long connection. The method for preventing the replay attacks to the long connection comprises the following steps: a client is connected to a server, and the server returns a random number to the client; the client performs HMAC calculation on a password used by a client user by using a composite key, and sends a plain text of a user name and an HMAC calculation result of the client to the server; the server inquires the password used by the corresponding client user after receiving the HMAC calculation result of the client, and also performs the HMAC calculation on the password used by the corresponding client user by using the composite key; and the HMAC calculation results obtained by the server and the client are compared, and if a comparison result shows consistency, the connection is retained, or the connection is cut off. The method for preventing the replay attacks to the long connection overcomes the shortcomings of the conventional replay attack prevention mode and realizes the replay attack prevention for the long connection; and the method is good in effect and wide in application range.

Description

technical field [0001] The invention relates to the technical field of information security, in particular to a method for preventing replay attacks of long connections. Background technique [0002] Replay Attacks, also known as replay attacks, replay attacks, or Freshness Attacks, refer to the attacker sending a packet that has been received by the destination host, especially in the authentication process, used to authenticate the identity of the user. Received packets to achieve the purpose of deceiving the system, mainly used in the identity authentication process, destroying the security of authentication. [0003] A replay attack is a type of attack. This attack repeats a valid data transmission maliciously or fraudulently. The replay attack can be carried out by the initiator intercepting and resending the data to the destination host. Attackers use network monitoring or other methods to steal authentication credentials, usually cookies or some authentication sessio...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

Application Information

Patent Timeline
no application Login to View More
Patent Type & AuthorityApplications(China)
IPC IPC(8): H04L9/08H04L9/32H04L29/06
CPCH04L9/0869H04L9/3242H04L63/06H04L63/1441
Inventor李朝铭李炫均
OwnerINSPUR SOFTWARE CO LTD