节点文献
基于共享信任技术的身份认证的研究
Research on Trust Partaking Identity Authentication
【作者】 王丽丽;
【导师】 蔡永泉;
【作者基本信息】 北京工业大学 , 计算机科学与技术, 2010, 硕士
【摘要】 随着社会的信息化发展,人们可以通过网络获得大量的信息资源和服务,人类进入信息化社会,这使得社会的开发程度进一步加大,与之俱来的是信息安全问题,信息安全已成为人们在信息空间中生存与发展的重要保证条件。作为信息安全的第一道屏障的身份认证技术,是现代密码学发展的重要分支。在一个安全系统设计中,用户在访问所有系统之前,首先应该经过身份认证系统识别身份,然后由安全系统根据用户的身份和授权数据库决定用户是否能够访问某个资源。传统的身份认证系统是由可信的认证中心为用户颁发证书以作为用户身份验证的凭证,但是这样的认证系统存在很大的缺陷,其安全性存在很大的隐患,隐患的根源就在于传统的认证中心是由一个部门或者一个权威充当,其保密性依赖于可信中心的正常工作,在参与者较多的情况下则很难进行证书的管理,可能会成为性能的瓶颈,造成可扩展性差的问题。基于上述情况,网络中通信的实体可以采用共享信任的思想,即单个参与者不可信,参与者集合可信。本文重点对身份认证中的共享信任身份认证及无可信中心的身份认证进行了系统,深入的研究并给出了共享信任身份认证方案的分类方案,主要的工作及创新如下:(1)在ElGamal密码体制的基础上,提出了一种基于ElGamal密码体制的共享信任身份认证方案,详细描述了初始化阶段、密钥生成阶段、子证书生成阶段、证书合成阶段和证书验证阶段,并在标准模型下对各个阶段进行了正确性和安全性分析,表明该方案是健壮、安全的。(2)针对在开放的网络环境中可信中心可能受到攻击,为防止网络欺骗,可信中心发来的证书需要可验证性。运用共享信任的思想,在可信CA的参与下,提出一种安全性既不完全依赖于CA,又不完全依赖于认证参与者的身份认证方案。详细阐述了从初始化到证书颁发过程,并对方案进行了安全性分析。(3)针对可信中心参与的身份认证过程可能造成功能和性能瓶颈的问题,提出一种无可信中心的共享信任身份认证方案,并分析其正确性和安全性。
【Abstract】 With the rapid development of the society’s informationization, people can get plentiful information resources and service through internet and we have stridden forward the informationization society. It has increased the exploitation extent and information security emerges as time requires. As we know, information security has become the vital guarantee qualification of survivorship and development in information spaces. Identity authentication as the first barrier of information security is an important filiations of the modern cryptology. While designing a safety system, before accessing the entire system, we must identify our figure through the identity authentication system. After that, the safety system will decide whether it can visit certain resource according to the user’s identity and the decision of authorization database.The traditional identity authentication system works like that it need a trusted center to award certificate to the user as credence of the user. There is great weakness in this system. It has hidden trouble in its security. The rootstock of it is the trusted center is act as one department or one authority. Its secrecy based on the trusted center’s in gear. It’s hard to manage the certificate while there are so many partners and will reach the bottle-neck of performance and may be difficult to extend. According to this circs, we can use the trust partaking ideology, which is a single partner is unlikelihood, but the union of partners is credible.The text focuses on the researching of trust partaking and identity authentication without a single trusted center. The main work in this thesis is as follows:(1) Based on the ElGamal cryptology system, the thesis proposes an ElGamal cryptology-based trust partaking identity authentication scheme and describes the initialization phase, key generation phase, sub-certificate generation phase, certificate composition phase in detail. After that, it gives the correctness and security analysis under standard pattern. It is proved to be robust and safe.(2) As the trusted center may be attacked under the opening internet environment, to keep from network spoofing, the certificate from the trusted center needs verification. By using trust partaking ideology, with the participation of trusted CA, the thesis proposes an identity authentication scheme whose security doesn’t depend on CA completely and doesn’t depend on authentication participant completely. It describes detail from the initialization phase to certificate composition phase and gives the security analysis of the scheme.(3) As we know, if there is a trusted center, it may cause bottle-neck in its function and performance. The thesis proposes a trust partaking identity authentication scheme and gives the analysis of its correctness and security.
【Key words】 discrete logarithm; bilinear pairings; identity authentication; trust partaking; threshold;