节点文献
基于IBC的SDP密钥安全方案设计
SCHEME OF SDP KEY SECURITY BASED ON IBC
【摘要】 SDP架构是实现零信任的原生解决方案,相比较传统的PKI体制零信任解决方案,基于IBC技术的零信任方案中的密钥管理结构简单,易于部署,只需更小的储存和通信开销,但SDP在SPA等环节上的密钥分发、撤销和更新机制设计存在不足。针对这种情况,运用仲裁与无仲裁两种管理机制重新构造基于IBC体制SDP密钥保护结构,并结合SM9算法设计SDP密钥生成、使用、撤销方案。通过分析,SPA协议在国产密码算法替代后有良好的实用性,该方案理论上能够实现密钥安全分发、快速撤销提高响应速度,相比传统的PKI方案和IBC方案,提供一种普适环境下低带宽和高响应速度的SDP密钥安全方案。
【Abstract】 The SDP architecture is a native solution to achieve zero trust. Compared with the traditional PKI-based zero trust solution, the key management structure in the IBC-based zero trust solution is simple and easy to deploy, requiring less storage and communication overhead, but the design of the SDP key distribution, revocation and update mechanism in the SPA and other links is inadequate. To address this situation, the IBC-based SDP key protection structure is reconstructed using both arbitration and arbitration-free management mechanisms, and the SDP key generation, usage, revocation and update scheme is designed in conjunction with the SM9 algorithm. Through analysis, the scheme can theoretically achieve secure key distribution, fast update and revocation, where the SPA protocol has good practicality after the replacement of domestic cryptographic algorithms, and provides a low-bandwidth and high-response-speed SDP key security scheme in a pervasive environment compared with the traditional PKI scheme and IBC scheme.
【Key words】 Zero trust; Self-controllable; Software defined perimeter; Identity-based cryptograph; Single packet authorization; Key security;
- 【文献出处】 计算机应用与软件 ,Computer Applications and Software , 编辑部邮箱 ,2026年03期
- 【分类号】TN918.4
- 【下载频次】18