节点文献

基于IBC的SDP密钥安全方案设计

SCHEME OF SDP KEY SECURITY BASED ON IBC

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 池亚平; 梁家铭; 范晓红; 薛德凡;

【Author】 Chi Yaping;Liang Jiaming;Fan Xiaohong;Xue Defan;Cyberspace Security Department, Beijing Electronic Science and Technology Institution;Key Laboratory of Network Assessment Technology, Institute of Information Engineering,Chinese Academy of Sciences;

【通讯作者】 梁家铭;

【机构】 北京电子科技学院网络空间安全系; 中国科学院信息工程研究所中国科学院网络测评技术重点实验室;

【摘要】 SDP架构是实现零信任的原生解决方案,相比较传统的PKI体制零信任解决方案,基于IBC技术的零信任方案中的密钥管理结构简单,易于部署,只需更小的储存和通信开销,但SDP在SPA等环节上的密钥分发、撤销和更新机制设计存在不足。针对这种情况,运用仲裁与无仲裁两种管理机制重新构造基于IBC体制SDP密钥保护结构,并结合SM9算法设计SDP密钥生成、使用、撤销方案。通过分析,SPA协议在国产密码算法替代后有良好的实用性,该方案理论上能够实现密钥安全分发、快速撤销提高响应速度,相比传统的PKI方案和IBC方案,提供一种普适环境下低带宽和高响应速度的SDP密钥安全方案。

【Abstract】 The SDP architecture is a native solution to achieve zero trust. Compared with the traditional PKI-based zero trust solution, the key management structure in the IBC-based zero trust solution is simple and easy to deploy, requiring less storage and communication overhead, but the design of the SDP key distribution, revocation and update mechanism in the SPA and other links is inadequate. To address this situation, the IBC-based SDP key protection structure is reconstructed using both arbitration and arbitration-free management mechanisms, and the SDP key generation, usage, revocation and update scheme is designed in conjunction with the SM9 algorithm. Through analysis, the scheme can theoretically achieve secure key distribution, fast update and revocation, where the SPA protocol has good practicality after the replacement of domestic cryptographic algorithms, and provides a low-bandwidth and high-response-speed SDP key security scheme in a pervasive environment compared with the traditional PKI scheme and IBC scheme.

【基金】 国家重点研发计划项目(2018YFB1004101)
  • 【文献出处】 计算机应用与软件 ,Computer Applications and Software , 编辑部邮箱 ,2026年03期
  • 【分类号】TN918.4
  • 【下载频次】18
节点文献中: