首页 | 本学科首页   官方微博 | 高级检索  
     

云环境下基于环签密的用户身份属性保护方案
引用本文:李拴保,傅建明,张焕国,陈晶,王晶,任必军.云环境下基于环签密的用户身份属性保护方案[J].通信学报,2014,35(9):99-111.
作者姓名:李拴保  傅建明  张焕国  陈晶  王晶  任必军
作者单位:1. 武汉大学空天信息安全与可信计算教育部重点实验室,湖北武汉430072;武汉大学计算机学院,湖北武汉430072;河南财政税务高等专科学校信息工程系,河南郑州451464
2. 武汉大学空天信息安全与可信计算教育部重点实验室,湖北武汉430072;武汉大学计算机学院,湖北武汉430072
3. 河南财政税务高等专科学校信息工程系,河南郑州,451464
基金项目:国家自然科学基金资助项目(61373168, 61202387, 61272451);教育部高等学校博士学科点专项科研基金资助项目(20120141110002);河南省软科学计划基金资助项目(132400410723, 142400410671)
摘    要:身份属性泄漏是最严重的云计算安全威胁之一,为解决该问题,提出了一种基于环签密的身份属性保护方案.该方案以云服务的数字身份管理为研究对象,论述了去中心化的用户密钥分割管理机制,用户自主选择算子在本地生成并存储密钥,从而令注册管理者(registrar)无法获得用户完全私钥,达到消除证书管理负载的目的.另外,本方案以用户访问权限为中心设计身份属性盲环签密验证机制,令用户和CSP组成环,基于环和自身属性用户可对消息子线性盲签密以及非交互公开密文验证,用以阻止多个CSP共谋导致的身份属性泄露场景,从而保护身份属性的完整性和机密性.最后,给出密文和属性强不可伪造、盲性机制的证明结果,在DBDH困难问题假设和适应性选择密文攻击下,方案中的用户可生成3个完全私钥组件,成功阻止环成员身份伪装.为验证系统有效性,围绕身份属性保护方案的综合负载问题对盲环签密算法进行性能评估,并对比同类算法以证实系统优化结果.

关 键 词:数字身份管理  无证书  强不可伪造性  盲性
收稿时间:1/5/2014 12:00:00 AM

Scheme on user identity attribute preserving based on ring signcryption for cloud computing
LI Shuan-bao , FU Jian-ming , ZHANG Huan-guo , CHEN Jing , WANG Jing , REN Bi-jun.Scheme on user identity attribute preserving based on ring signcryption for cloud computing[J].Journal on Communications,2014,35(9):99-111.
Authors:LI Shuan-bao  FU Jian-ming  ZHANG Huan-guo  CHEN Jing  WANG Jing  REN Bi-jun
Affiliation:1. Key Lab of Aerospace Information Security and Trusted Computing Ministry of Education,Wuhan University,Wuhan 430072,China;2. School of Computer,Wuhan University,Wuhan 430072,China;3. Department of Information Engineering,Henan College of Finance and Taxation,Zhengzhou 451464,China
Abstract:Identity attribute leak as the most severe security threat of cloud computing, in order to solve this problem, a protection scheme of identity attributes based on ring signcryption was proposed. Focused on digital identity management in cloud service, which discusses user key parting management with decentralization. Users can choose some seeds for generation and storage of key, then integrated user key cannot be acquired by registrar, based on this payload on certification management is reduced. In addition, access-centric blindness ring signcryption verification for identity attribute is designed, which constitutes ring of users and CSP, combined with own attribute users can accomplish ring-oriented sub-linear blindness signcryption and non-interactive public ciphertext verifiability for messages so that integrity and confidentiality of identity attribute can be protected avoiding identity attribute leakage in collusion of multi-CSP. At last, strong blindness and unforgeability of ciphertext and attribute is proved in proposed model, three private key components can be generated by users and identity forgeability of ring member can be prevented successfully on the condition of DBDH difficult assumption and adaptive chosen-ciphertex tattacking. Effectiveness of proposed mechanism is verified via performance evaluation of blindness ring signcryption algorithm based on comprehensive payload in identity attribute protection, and optimization is confirmed compared with similar algorithms.
Keywords:digital identity management  certificateless  strong unforgeability  blindness
点击此处可从《通信学报》浏览原始摘要信息
点击此处可从《通信学报》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号