节点文献

秘密共享体制与访问控制方法研究

Research of Secret Sharing Scheme and Access Control Method

【作者】 李平

【导师】 谢端强;

【作者基本信息】 国防科学技术大学 , 计算数学, 2005, 硕士

【摘要】 随着网络应用的普及、网络覆盖范围的扩大和各种网络技术的不断发展,网络安全问题变得日益重要。密码是网络安全的核心技术,加密与解密、数字签名、身份认证和密钥交换等技术是保障网络安全的重要机制,这些技术的安全性是基于密钥的秘密性。秘密共享方案与门限密码体制从不同的角度保护了密钥的安全性,这些领域一直是信息安全领域研究的热点,IEEE P1363标准委员会将门限密码体制列为未来标准研究内容之一,并且它们为一些特殊的应用场合,提供了安全解决方案。 (t,n)门限方案是实现秘密共享的最常用、最有效的方式。攻击者必须获得超过门限的秘密份额数,才能重构系统的密钥,这样做既增加了攻击难度,又解决了权力集中的问题,只有通过超过门限的参与者同意才能完成加解密或数字签名等操作。 本文首先分析了一种基于计算机代数的秘密共享方案,从理论上讨论了用正则列方法构造的秘密共享方案的安全性,指出了在某种条件下这种方案的安全缺陷,同时给出了一个攻击例子,并且对所给的例子进行了分析,可以在不达到门限值的情况下重构秘密。 通过对用户层级中动态访问控制方案的研究,提出了两种新的层级结构下的信息访问控制方案,我们从提高安全性、减少计算量、节省存储空间等方面作为方案设计的主要依据,同时对用户类的增加/删除,用户类关系的增加/删除,用户类秘密密钥的变更等动态的存取控制问题也进行了讨论。一种方案的安全性证明是基于离散对数问题;另一种方案的安全性证明是基于判定性DH假设。

【Abstract】 With the popularization of the network application, the expansions of the network cover scope and the development of all kinds’ network technology. The network information security became more and more important. Cryptography is the center of network security technology, in which the encryption and decryption, digital signature, identity authentication are important mechanism to protect information security. The security of them is based on the secret of private key. If private key leaked, the security of these mechanisms will be destroyed. Secret sharing scheme and threshold cryptosystem protect the security of private key in different way, and they provide some security scheme for some special application. These areas are worth studying. IEEE P1 363 makes threshold cryptosystem one of the studying content of the future standard.(t,n) threshold scheme is an easy and efficient way to secret sharing. Attackers must get more than threshold shares so that they can resume the privacy. This increases the difficulty and at the same time solves the power concentrated problem, because decryption and encryption and digital signature can be finished only after more than threshold participants’ agreement.In this paper, we first discuss the security of the secret sharing scheme constructed by regular sequence, and analysis the security of the example constructed by regular sequence. The exmple show that we can restore the secret without enough threshold participants’ agreement. This is a security bug of the scheme.Then we present two new access control schemes based on the schemes of dynamic access control in the user hierarchy before. We design the scheme mainly focusing on security, computation quantity and storage. The dynamic access control problems, such as, adding/deleting user classes, adding/deleting user relationships, and changing secret keys, are discussed. The security proof of the first scheme is based on the disperse logarithm problem (DLP); the security proof of the second scheme is based on decisional Diffie-Hellman (DDH) assumption.

  • 【分类号】TN918
  • 【下载频次】128
节点文献中: