GB/T 15843.4-2024 Cybersecrity technology—Entity authentication—Part 4:Mechanisms using a cryptographic check function
GB/T 15843.4-2024 Cybersecrity technology—Entity authentication—Part 4:Mechanisms using a cryptographic check function
Basic Information
Scope
This document specifies the entity authentication mechanism using password verification functions, including one-way authentication and two-way authentication. This document is applicable to the design, development, implementation, and testing of entity authentication using password verification functions. The mechanisms specified in this document use time-varying parameters such as timestamps, serial numbers, or random numbers to prevent previously valid authentication information from being accepted after its expiration. If a timestamp or serial number is used, one-way authentication only requires one transmission, while two-way authentication requires two transmissions. If a challenge-response method using random numbers is used, one-way authentication requires two transmissions, and two-way authentication requires three transmissions. Examples of password verification functions are provided in GB/T 15852 (all parts).