节点文献

基于凸壳理论与信息隐藏的数字签名技术方案之改进探索

An Improvement and Exploration for Digital Signature Technology Based on Convex Hull Theory and Information Hiding

【作者】 张乐

【导师】 周启海;

【作者基本信息】 西南财经大学 , 金融贸易电子商务, 2008, 硕士

【摘要】 随着计算机软/硬件技术、网络通信等高新技术(尤以Internet为代表)的迅猛发展与广泛应用,促成了电子商务方式、模式、系统的应运而生。电子商务的重要核心之一,在于通过网络信息技术来传递商业信息和进行网络交易。伴随着电子商务的普遍推行,其高度依赖于计算机自身以及计算机网络技术安全的基本特征越来越明显,而互联网所具有的自由、开放性则不可避免地使电子商务系统面临着各种各样的网上安全隐患与威胁。作为安全内容之一的商务交易安全,必须能够有效防止信息在网络传输途中被窃读、篡改,防止第三方冒充他人身份进行诈骗,防止商务各方否认所接收到的消息或抵赖交易行为的发生,等等。要实现对商务交易的安全性监控,就得使用数字签名技术,而数字签名技术已在确保信息的完整性以及交易的不可否认性等方面有了不菲的建树。自然,电子商务交易中的商务各方,大多是在虚拟的网络空间下、以非面对面的方式进行其商务交易。显然,诸如在虚拟的网络交易中如何建立起商务各方之间的相互信任关系、在商务纠纷发生后如何裁决特定各方的责任等电子商务活动,都必然会涉及到交易各方的身份确认和信息归属。数字签名出现在整个电子商务交易过程中,其极力化解这些不确定因素,充当起安全保障的基础和起点。从而,使数字签名技术逐步得到普及推广与广泛应用,成为创建安全、可靠的网上交易环境的重要一环。然而,作为一种网络安全技术手段,数字签名在保障电子商务交易安全的同时,自身也存在着诸多安全隐患与缺点;故有必要对其加以研究,从多角度探讨实现电子商务不同交易需求下的数字签名技术改进方案。数字签名,是对手书签名的继承和发展。它指:采用一定的数据交换协议,使用密码算法对数据单元或附加在数据单元上的一些数据,进行特约数据处理与等价密码变换,并基于这种特约数据处理与等价密码变换而允许数据单元的接收者用以确认数据单元来源和数据单元的完整性,以保护数据,防止被他人(例如对方接收者)进行伪造。故数字签名是基于加密技术的一种信息认证技术,在网络中的密钥分配、电子商务安全交易等方面都有重要应用。信息认证的目的有两个:一是验证信息的发送者是真正的发送者,还是冒充的,电子商务一般是非面对面地交易,从保护交易主体的利益出发,每一笔交易在达成前,商务各方首先应该能相互确认交易对方是谁;二是验证信息的完整性,即验证信息在传送或存储过程中是否被篡改、重放或延迟等。类似现实生活中的手书签名或印章,接收方能够对其进行验证,从而判断发送者身份以及原文的真伪。签名机制的本质特征是该签名只能通过签名者自己确认的专用私密信息才能产生,即一个签名者的签名只能惟一的由他自己自主产生。当收、发双方发生争议时,第三方(仲裁机构)能够根据消息上的签名来裁定这条消息是否确实由发送方发出,从而实现抵赖性安全防范服务。数字签名的概念自从1976年被提出来以后,引起了密码学专家以及计算机专家们的普遍关注。1985年Elgamal所提出的基于有限域上离散对数问题的Elgamal数字签名方案,是数字签名历史上的一个里程碑。此后,美国国家安全局和国家标准局通力合作,于1991年提出了美国的数字签名标准DSS及其算法标准DSA,而DSA数字签名算法则是最初的Elgamal算法的变种。随着计算机技术、网络通信技术的飞速发展以及应用需求的复杂化,数字签名技术也从最初意义上的单人签名、单人验证的模式扩展到多人签名、综合验证的领域。因此,一些专家学者根据网络环境下各种不同的应用需求,先后设计出多种附加其他功能的数字签名方案,如:不可否认签名、盲签名、双重签名、群签名、批量签名、门限签名以及代理签名等。这些都极大地丰富了数字签名的应用与实践基础,促进了数字签名的不断发展、日益普及与广泛应用。数字签名作为网络时代必备的核心技术,其普及与应用还需要得到法律上的支持与保障。美国、新加坡、日本、韩国、欧盟等电子商务发展得比较早的国家和地区都已相继通过相关法案赋予数字签名以法律效力。从1995年美国犹他州颁布《数字签名法》至今,各国以及相关的国际组织纷纷起草、制定相关立法,目前已有近70个国际组织和地区颁布了与电子商务及电子签名相关的立法,其中较重要或影响较大的有:联合国贸易法委员会1996年颁布的《电子商务示范法》、2000年颁布的《电子签名统一规则》以及2001年颁布的《电子签字示范法》;欧盟颁布的《关于内部市场中与电子商务有关的若干法律问题的指令》和《电子签名统一框架指令》;美国2000年颁布的《国际与国内商务电子签名法》、《统一电子交易法》以及《统一计算机信息交易法》;亚洲国家如新加坡1998年颁布了《电子交易法》;我国香港2000年颁布的《电子交易条例》等。我国于2004年3月通过了《中华人民共和国电子签名法(草案)》,并在此基础上,十届人大于2004年8月28日正式通过《中华人民共和国电子签名法》,并决定于2005年4月1日起正式施行。同时,2005年4月1日,信息产业部还同时颁布实施了《电子认证服务管理办法》,目的在于保证《电子签名法》的顺利施行。本文的基本架构与主要内容,是:首先,就电子商务的安全隐患以及安全需求入手,较详细地介绍了电子商务的安全技术,并由此引入数字签名技术;其次,对数字签名的定义、安全特性、分类以及实现过程作了阐述,并针对数字签名实现过程中出现的种种安全隐患(如:拦截窃读、密文存放位置明显易引起攻击等)以及不同用户的交易需求进行了若干分析,探讨了数字签名的非隐藏型改进方案,并将信息隐藏技术引入数字签名技术的研究,提出隐藏型数字签名的概念与方法,进而设计出了基于非对称加密与信息隐藏技术的全密数字签名改进方案及局密数字签名改进方案;再次,为了对数字签名技术方案进行精准化细分与选择,提出了“安全/速度比”这一评估指标,以指导和适应用户对数字签名技术方案的精准化选择;最后,对凸壳理论的相关概念、应用背景以及几大凸壳生成经典算法进行了介绍,并指出几大凸壳生成算法的优缺点。在此基础之上,本文提出了基于凸壳理论的数字签名技术改进方案。它详细阐述了凸壳生成的基础——坐标轴上的坐标是如何选取并构建的、基于凸壳理论的数字签名改进方案的实现过程以及对该方案的评价。

【Abstract】 With the rapid development and extensive application of the computer software/hardware technology, communication technology and the network technology (especially represented by the Internet), the traditional work methods and business model has encountered a huge impact, at the same time, e-commerce model and system came into being. One of the important cores of e-commerce is that we can transfer the commercial information and conduct the network transactions through the network. Along with the implementation of e-commerce, the basic characteristics that it is highly dependent on the computer and the security of computer network technology become obvious increasingly, however, the Internet is so free and open that the e-commerce system will inevitably be faced with a variety of the security hiding dangers and threats from the internet. As one part of the security content, the commercial transaction security must prevent the information from being read secretly and tampered with through the network transmission, prevent the third parties which act as the fake identity from doing the fraud in the online transaction, guarantee that the commercial credit and the business act undeniable, and ensure that the transaction and information which has been done can not be denied by the business parties, and so on. In order to achieve the monitor of commercial transaction security, we have to use the digital signature technology, and the digital signature technology has got great achievement in several aspects, in which ensure the integrity, security, timeliness, privacy and irreversibility of the business information through the transmission. Naturally, the business parties mostly conduct the transactions non-face-to-face under the virtual cyberspace in the e-commerce transactions. Clearly, the e-commerce activities, such as how to let the business parties trust each other in the virtual cyberspace and how to arbitrate the parties’specific obligation while occurring the business disputes, will inevitably involve the identity confirmation of the business parties and the information attribution. The digital signatures, which exist in the whole process of the e-commerce transactions, resolve the uncertain factors strongly and server as the basis and the starting point of the security. Thus, the digital signature technology, which achieves the rapid spread and the extensive application gradually, becomes an important link of the creation of a safe, reliable online transaction environment. However, as a means of the network security technology, digital signatures also exist a lot of security hiding troubles and weaknesses while guaranteeing the e-commerce security; Therefore, it is necessary to research the digital signature technology and discuss the digital signature technology improvement program under the different transaction demands from various angles.Digital signature which is relative to the handwritten signature plays a major, approval and the effective role. It uses the certain data exchange protocol and encryption algorithm to treat the data attached itself to data unit with special data disposal and equivalent cryptogram transformation, which allow the receivers to confirm the source and integrity of the trading information, and protect the trading information from being forged by someone such as the receivers. So, The digital signature is an information authentication technology based on encryption technology. The concept of digital signature was raised in 1976. Since then, it has aroused cryptography experts’and computer experts’widespread concern. With the rapid development of computer technology, network communication technology and the complexity of application needs, the digital signature technology extends from the initial sense of the single signature, single verification model to the more signature, comprehensive verification area. Therefore, according to the various application needs under the network environment, some experts and scholars has designed a variety of digital signature schemes which contain other additional functions, such as: undeniable signature, blind signature, double signature, group signature, batch signature, proxy signature. All of these signature schemes have greatly enriched the application and practice basis of the digital signature, and have promoted the continuous development, the growing popularity and the wide application of digital signature.As a core technology of the Internet era, Digital signature is absolutely necessarily, its popularization and application also need the support and protection of the law. Some countries and regions such as the United States, Singapore, Japan, Korea, the European Union, which developed e-commerce earlier than any other countries and regions, have adopted laws to endow digital signature with force adeffect. And, in our country, the" Electronic Signature Law of the People’s Republic of China" went into effect as of April 1, 2005.In this paper, the basic framework and main contents are:First, the paper starts with the security hiding troubles and security needs of e-commerce, introduces the security technology of e-commerce in more detail, and thus leads to the digital signature technology;Secondly, the paper expatiates the definition, security characteristics, classification, as well as the process of digital signature, analyzes the various security hiding troubles appearing in the realization process of the digital signatures (such as: interception Reading, attack easily for the obvious storage location of the ciphertext) and different users’demands for the transactions, discusses the non-hiding-improvement of the digital signature, and introduces the information hiding technology into the digital signature research, raises the concept and method of the hiding digital signature, then designs the whole encrypted digital signature and local encrypted digital signature which based on the asymmetric encryption and information hiding technology;Thirdly, in order to fractionizes and chooses the digital signature schemes fine, the paper raises a "safety/speed ratio "evaluation indicator;Finally, the paper introduces the related concepts and application background of the convex hull theory, as well as some classical convex hull generating algorithm, and points out the advantages and disadvantages of the convex hull generating algorithm. On this basis, the paper raises a digital signature improving scheme which based on the convex hull theory. It elaborates that how to choose and establish the coordinate of the coordinate axis which is the base of the convex hull generation, the realization process of the digital signature improving scheme which based on the convex hull generating algorithm, and the evaluation of the scheme.

【关键词】 数字签名信息隐藏凸壳
【Key words】 Digital signatureInformation hidingConvex hull
节点文献中: 

本文链接的文献网络图示:

本文的引文网络