节点文献

一种基于权能标识的三方安全协议的设计和分析

Design and Analysis of a Capability-based Third-Party Security Protocol

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 黄建忠谢长生朱光喜罗东健

【Author】 HUANG Jian-Zhong1,2 XIE Chang-Sheng1 ZHU Guang-Xi2 LUO Dong-Jian1 (Key Laboratory of Data Storage System, Huazhong University of Science and Technology, Wuhan 430074)1 (Dept. of Electronic & Information Engineering, Huazhong University of Science and Technology,Wuhan 430074)2

【机构】 华中科技大学数据存储教育部重点实验室华中科技大学电子与信息工程系华中科技大学数据存储教育部重点实验室 武汉430074华中科技大学电子与信息工程系武汉430074武汉430074

【摘要】 随着数据密集型应用的发展,网络存储的安全性成为研究热点。针对大规模存储系统的可扩展性和安全性的要求,本文提出了一种基于三方传输模式的存储安全系统框架,并设计了一种基于权能标识的三方安全协议,该协议的最大特点是传输安全性和访问控制机制二者独立。通过对三方安全协议的形式化分析和推导,从逻辑上验证请求中权能标识的完整性、协议传输过程的正确性,以及消息的真实性,从而确保了三方安全协议的可行性。

【Abstract】 With the growth of data-intensive application, networked storage security becomes hotpot of research. Aiming at the scalability and security requirement of large-scale storage system, a storage security framework basing on third-party transferring mode is proposed, and a capability-based third-party security protocol separating transfer security from access control mechanism is designed. After the formal analysis, it is clear that the deducing results logically validate the integrity of requested capability, correctness of transfers process and authenticity of message, thus guaranteeing the feasibility of the third-party security protocol.

【基金】 国家“973”重大基础研究项目(2004CB318203);国家自然科学基金(60603074)资助
  • 【文献出处】 计算机科学 ,Computer Science , 编辑部邮箱 ,2007年03期
  • 【分类号】TP393.08
  • 【被引频次】4
  • 【下载频次】86
节点文献中: 

本文链接的文献网络图示:

本文的引文网络