网络与信息安全学报 ›› 2018, Vol. 4 ›› Issue (3): 42-50.doi: 10.11959/j.issn.2096-109x.2018027

• 论文 • 上一篇    下一篇

面向隐私保护的服务调用安全认证协议设计

柴林鹏1,2(),张斌1,2,刘洋1,2,孙佳佳1,2   

  1. 1 信息工程大学,河南 郑州 450001
    2 河南省信息安全重点实验室,河南 郑州 450001
  • 修回日期:2018-02-04 出版日期:2018-03-01 发布日期:2018-04-09
  • 作者简介:柴林鹏(1993-),男,山西临汾人,信息工程大学硕士生,主要研究方向为信息安全。|张斌(1969-),男,河南郑州人,信息工程大学教授、博士生导师,主要研究方向为网络空间安全。|刘洋(1980-),男,河南南阳人,信息工程大学讲师,主要研究方向为信息系统安全。|孙佳佳(1987-),男,河南洛阳人,博士,信息工程大学讲师,主要研究方向为信息对抗与信息安全。
  • 基金资助:
    河南省基础与前沿技术研究计划基金资助项目(142300413201);信息保障技术重点实验室开放基金资助项目(KJ-15-109);信息工程大学新兴科研方向培育基金资助项目(2016604703)

Design of privacy-preserving authentication protocol for service invocation

Linpeng CHAI1,2(),Bin ZHANG1,2,Yang LIU1,2,Jiajia SUN1,2   

  1. 1 Information Engineering University,Zhengzhou 450001,China
    2 Henan Province Information Security Key Laboratory,Zhengzhou 450001,China
  • Revised:2018-02-04 Online:2018-03-01 Published:2018-04-09
  • Supported by:
    The Basic and Advanced Technology Research Project of Henan Province(142300413201);Open Fund Project of Key Laboratory of Information Assurance(KJ-15-109);Information Engineering University Emerging Research Direction Project of Information Engineering University(2016604703)

摘要:

针对 SOA 多域协作中认证信息的安全传递和用户隐私保护需求,基于现有可证安全的无证书聚合签密方案提出一种面向隐私保护的服务调用安全认证协议。根据服务调用路径逐次对认证信息进行聚合签密,有效支持服务提供方能够动态加入到服务调用认证流程;分别利用聚合签密方案和DH(Diffie-Hellman)算法确保SOAP消息中认证信息和共享信息的机密性,使SOAP消息中的隐私信息仅能被指定的服务提供方解密,有效控制了隐私信息的披露范围;同时利用聚合签密方案的公开可验证性确保服务调用流程中的其余服务提供方能够验证聚合签密值的有效性。与其他协议相比,缩短了SOAP消息的长度,提高了消息传输效率。

关键词: SOA多域协作, 服务调用认证, 隐私保护, 无证书聚合签密, DH算法

Abstract:

Aiming at the requirement of the safe transmission of authentication credentials and the privacy preserving in service orientied multi-domain collaboration environment,a privacy-preserving authentication protocol for service invocation based on the provable secure certificateless aggregate signcryption scheme was proposed.By the path of the service invocation,the authentication information has been signcrypted successively,ensuring that the service providers can dynamically and orderly join in the process of service invocation authentication.The credentials and shared information can be safely transmitted respectively by the aggregate signcryption scheme and Diffie-Hellman algorithm,thus the SOAP message only can be decoded by specified acceptor,which is suitable for controlling the disclosure scope of the privacy information.Simultaneously,the public verifiability of CLASC can ensure that the validity of the aggregate signcryption can be verified by other service providers.The length of the SOAP message is shorter than existed protocols,which improve the transfer efficiency.

Key words: service orientied multi-domain collaboration, service invocation authentication, privacy protection, certificateless aggregate signcryption, diffie-hellman algorithm

中图分类号: 

No Suggested Reading articles found!