首页 | 本学科首页   官方微博 | 高级检索  
     

基于可转换代理签密的SAML跨域单点登录认证协议
引用本文:王冠众,张 斌,费晓飞,熊厚仁.基于可转换代理签密的SAML跨域单点登录认证协议[J].计算机科学,2015,42(4):106-110, 115.
作者姓名:王冠众  张 斌  费晓飞  熊厚仁
作者单位:解放军信息工程大学三院 郑州450001
基金项目:本文受河南省基础研究计划项目(142300413201)资助
摘    要:可转换代理签密算法具有保护用户隐私、抗重放攻击、抗抵赖性等优势,基于该算法提出一种SAML跨域单点登录协议(SSPCPS).通过用户与异构域服务器直接交互认证,简化了跨域单点登录认证过程.用户身份票据由双方公钥结合用户随机选取的参数而生成,以密文形式传输,攻击者即使窃取该令牌也无法调用服务.用户利用代理签名密钥对摘要进行签密,在减少计算量的同时也可保证用户隐私安全.SSPCPS协议基于DH算法协商会话密钥,简化了会话密钥分发过程并降低了管理成本.使用CK安全模型证明了本协议的安全性并进行了性能分析,结果表明协议具有前向保密性、消息完整性等特点,同时在生成票据计算量和计算时间方面优于SSPPS协议、Juang方案、Ker-beros机制等.

关 键 词:代理签密  单点登录  安全断言标记语言  认证

SAML Cross-domain Single Sign-on Authentication Protocol Based on Convertible Proxy Signcryption
WANG Guan-zhong,ZHANG Bin,FEI Xiao-fei and XIONG Hou-ren.SAML Cross-domain Single Sign-on Authentication Protocol Based on Convertible Proxy Signcryption[J].Computer Science,2015,42(4):106-110, 115.
Authors:WANG Guan-zhong  ZHANG Bin  FEI Xiao-fei and XIONG Hou-ren
Affiliation:The Third Institute,The PLA Information Engineering University,Zhengzhou 450001,China,The Third Institute,The PLA Information Engineering University,Zhengzhou 450001,China,The Third Institute,The PLA Information Engineering University,Zhengzhou 450001,China and The Third Institute,The PLA Information Engineering University,Zhengzhou 450001,China
Abstract:Convertible proxy signcryption algorithm has the advantages of protecting user privacy,anti-replay attack,anti-disavowal etc.A SAML cross-domain single sign-on authentication protocol (SSPCPS) was proposed based on the algorithm.Through user and heterogeneous domain server interacting and authenticating directly,the protocol simplifies the process of SSO authentication.User token is generated by combining selected random parameters with the public key,and is transferred in the secret form,improving the security of protocol.The attacker cannot use the service,even though the token is stolen.Proxy signature key is used to signcrypt the digest,reducing the amount of computation,and ensuring the privacy of user as well.Session key is negotiated based on DH algorithm,simplifying the distribution process as well as reducing the management cost.The security of the protocol was proved by CK security model and performance analysis was presented.The result indicates that the protocol holds the features of forward secrecy,message integrity,etc,and the amount of computation and the computation time of generating token are better than SSPPS protocol,Juang scheme and Kerberos scheme,etc.
Keywords:Proxy signcryption  Sigle-sign-on  SAML  Authentication
本文献已被 万方数据 等数据库收录!
点击此处可从《计算机科学》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号