Journal of South China University of Technology (Natural Science Edition) ›› 2007, Vol. 35 ›› Issue (1): 94-98.

• Computer Science & Technology • Previous Articles     Next Articles

Authentication and Key Exchange Scheme Based on SRP-6 Protocol

Li Dong  Guo He-qing  Han Tao   

  1. School of Computer Science and Engineering , South China Univ. of Tech. , Guangzhou 510640 , Guangdong , China
  • Received:2005-09-12 Online:2007-01-25 Published:2007-01-25
  • Contact: 李冬(1974-) ,男,博士生,主要从事网络信息系统安全方面的研究。 E-mail:flyindog@163.com
  • About author:李冬(1974-) ,男,博士生,主要从事网络信息系统安全方面的研究。
  • Supported by:

    国家"973" 计划项目( G20000263 )

Abstract:

In order to solve the problem of authentication in Web services , the key exchange mechanism of Secure Rernote Password-6 (SRP- 6) is analyzed , and a new authentication and key exchange scheme named SRP-over-SOAP is proposed. The proposed scheme , which is based on the Simple Object Access Protocol (SOAP) and the SRP-6 , branches out SOAP message and assigns the label of < SRPAuth > to SOAP header. Thus , the SRP au thentication in the transportation of SOAP message can be implemented. Moreover , by applying the proposed scheme to Web services , a bi-directional authentication between the server and the client server can also be imple-mented.

Key words: SRP protocol, Simple Object Access Protocol, authentication, key exchange, Web service