网络与信息安全学报 ›› 2018, Vol. 4 ›› Issue (5): 32-38.doi: 10.11959/j.issn.2096-109x.2018040

• 学术论文 • 上一篇    下一篇

基于证书的匿名跨域认证方案

丁永善,李立新,李作辉   

  1. 信息工程大学三院,河南 郑州 450001
  • 修回日期:2018-04-16 出版日期:2018-05-01 发布日期:2018-08-04
  • 作者简介:丁永善(1992-),男,河南周口人,信息工程大学硕士生,主要研究方向为信息安全。|李立新(1967-),男,重庆人,博士,信息工程大学研究员,主要研究方向为数据库、信息安全。|李作辉(1981-),男,湖南衡阳人,博士,信息工程大学副研究员,主要研究方向为信息安全。
  • 基金资助:
    国家重点研发计划基金资助项目(2017YFB0802100);国家重点研发计划基金资助项目(2016YFB0501900)

Certificate-based cross-domain authentication scheme with anonymity

Yongshan DING,Lixin LI,Zuohui LI   

  1. The 3rd College,Information Engineering University,Zhengzhou 450001,China
  • Revised:2018-04-16 Online:2018-05-01 Published:2018-08-04
  • Supported by:
    The National Key R&D Plan Program of China(2017YFB0802100);The National Key R&D Plan Program of China(2016YFB0501900)

摘要:

针对物联网中移动设备的跨域认证问题,提出一种基于证书的匿名跨域认证方案。首先,结合PKI和IBS的相关特性,提出一种基于证书的签名(CBS,certificate based signature)方案,并对提出的CBS方案的安全性进行了证明。方案中签名的验证结果为常量,保证跨域过程中认证实体的匿名性。该签名方案不仅避免了复杂的对运算,而且避免了传统PKI中复杂的证书管理和IBS中的密钥托管和分发问题。然后,基于CBS方案设计了一种适用于移动设备的跨域认证方案,该算法能在安全、高效的同时保证认证的匿名性。最后,同其他跨域认证方案进行了对比,对比结果表明,所提方案具有更强的安全性和更小的计算和通信开销,为计算能力和功率受限的移动设备进行跨域认证提供了一种较为实用的解决方案。

关键词: 移动设备, 跨域认证, 匿名, CBS, 对运算

Abstract:

Considered the cross-domain authentication of mobile devices in the Internet of things,a certificate based anonymous cross-domain authentication scheme was proposed.First,combined with the characteristics of PKI and IBS,a certificate based signature (CBS) algorithm was proposed,and the security of the proposed CBS scheme was proved.The verification result of the signature in the algorithm was constant,which ensured the anonymity of the authentication entities in the cross-domain process.The algorithm does not contain pairing,and avoids complex certificate management in traditional PKI and the key escrow and distribution of IBS.Then a cross-domain authentication scheme for mobile devices was constructed by combining the proposed signature algorithm.The scheme ensures the anonymity of authentication at the same time.Finally,compared with other schemes,the scheme proposed is more secure and has less computation cost and communication cost.Moreover,the scheme is simple and efficient,and could be applied to the cross-domain authentication of mobile devices.

Key words: mobile devices, cross-domain authentication, anonymity, CBS, pairing

中图分类号: 

No Suggested Reading articles found!