通信学报 ›› 2014, Vol. 35 ›› Issue (9): 99-111.doi: 10.3969/j.issn.1000-436x.2014.09.010

• 论文Ⅱ • 上一篇    下一篇

云环境下基于环签密的用户身份属性保护方案

李拴保1,2,3,傅建明1,2,张焕国1,2,陈晶1,2,王晶1,2,任必军3   

  1. 1 武汉大学 空天信息安全与可信计算教育部重点实验室,湖北 武汉 430072
    2 武汉大学 计算机学院,湖北 武汉 430072
    3 河南财政税务高等专科学校 信息工程系,河南 郑州 451464
  • 出版日期:2014-09-25 发布日期:2017-06-14
  • 基金资助:
    国家自然科学基金资助项目;国家自然科学基金资助项目;国家自然科学基金资助项目;教育部高等学校博士学科点专项科研基金资助项目;河南省软科学计划基金资助项目;河南省软科学计划基金资助项目

Scheme on user identity attribute preserving based on ring signcryption for cloud computing

Shuan-bao LI1,2,3,Jian-ming FU1,2,Huan-guo ZHANG1,2,Jing CHEN1,2,Jing WANG1,2,Bi-jun REN3   

  1. 1 Key Lab of Aerospace Information Security and Trusted Computing Ministry of Education,Wuhan University,Wuhan 430072,China
    2 School of Computer,Wuhan University,Wuhan 430072,China
    3 Department of Information Engineering,Henan College of Finance and Taxation,Zhengzhou 451464,China
  • Online:2014-09-25 Published:2017-06-14
  • Supported by:
    The National Natural Science Foundation of China;The National Natural Science Foundation of China;The National Natural Science Foundation of China;The Specialized Research Fund for the Universities Doctoral Discipline Ministry of Education;The Soft Science Scheme of Henan Province;The Soft Science Scheme of Henan Province

摘要:

身份属性泄漏是最严重的云计算安全威胁之一,为解决该问题,提出了一种基于环签密的身份属性保护方案。该方案以云服务的数字身份管理为研究对象,论述了去中心化的用户密钥分割管理机制,用户自主选择算子在本地生成并存储密钥,从而令注册管理者(registrar)无法获得用户完全私钥,达到消除证书管理负载的目的。另外,本方案以用户访问权限为中心设计身份属性盲环签密验证机制,令用户和CSP组成环,基于环和自身属性用户可对消息子线性盲签密以及非交互公开密文验证,用以阻止多个CSP共谋导致的身份属性泄露场景,从而保护身份属性的完整性和机密性。最后,给出密文和属性强不可伪造、盲性机制的证明结果,在DBDH困难问题假设和适应性选择密文攻击下,方案中的用户可生成3个完全私钥组件,成功阻止环成员身份伪装。为验证系统有效性,围绕身份属性保护方案的综合负载问题对盲环签密算法进行性能评估,并对比同类算法以证实系统优化结果。

关键词: 数字身份管理, 无证书, 强不可伪造性, 盲性

Abstract:

Identity attribute leak as the most severe security threat of cloud computing,in order to solve this problem,a protection scheme of identity attributes based on ring signcryption was proposed.Focused on digital identity management in cloud service,which discusses user key parting management with decentralization.Users can choose some seeds for generation and storage of key,then integrated user key cannot be acquired by registrar,based on this payload on certifica-tion management is reduced.In addition,access-centric blindness ring signcryption verification for identity attribute is designed,which constitutes ring of users and CSP,combined with own attribute users can accomplish ring-oriented sub-linear blindness signcryption and non-interactive public ciphertext verifiability for messages so that integrity and confidentiality of identity attribute can be protected avoiding identity attribute leakage in collusion of multi-CSP.At last,strong blindness and unforgeability of ciphertext and attribute is proved in proposed model,three private key components can be generated by users and identity forgeability of ring member can be prevented successfully on the condition of DBDH difficult assumption and adaptive chosen-ciphertex tattacking.Effectiveness of proposed mechanism is verified via performance evaluation of blindness ring signcryption algorithm based on comprehensive payload in identity attribute protection,and optimization is confirmed compared with similar algorithms.

Key words: digital identity management, certificateless, strong unforgeability, blindness

No Suggested Reading articles found!