信息网络安全 ›› 2017, Vol. 17 ›› Issue (10): 63-68.doi: 10.3969/j.issn.1671-1122.2017.10.010

• • 上一篇    下一篇

基于身份的指定验证者签名在跨域认证中的应用

王柳, 曹珍富(), 董晓蕾   

  1. 华东师范大学计算机科学与软件工程学院,上海 200240
  • 收稿日期:2017-08-01 出版日期:2017-10-10 发布日期:2020-05-12
  • 作者简介:

    作者简介: 王柳(1990—),女,山东,硕士研究生,主要研究方向为密码学;曹珍富(1962—),男,江苏,教授,博士,主要研究方向为密码学、数论;董晓蕾(1971—),女,江苏,教授,主要研究方向为数论、密码学。

  • 基金资助:
    国家自然科学基金[61632012, 61373154]

Research on Application of ID-based Designated Verifier Signature in Cross-domain Authentication

Liu WANG, Zhenfu CAO(), Xiaolei DONG   

  1. Department of Computer Science and Engineering, East China Normal University, Shanghai 200240, China
  • Received:2017-08-01 Online:2017-10-10 Published:2020-05-12

摘要:

云计算使用户能够更加便捷地获取各种资源,而用户在获取云服务时的身份认证技术也是云计算安全领域的关键问题。针对在跨域认证中使用OpenID方案容易出现钓鱼攻击、重放攻击等各种漏洞,文章应用基于身份的秘钥交换协议和基于身份的指定验证者签名构造了一个跨域身份认证方案,利用基于身份的秘钥交换和指定验证者的签名的特点来解决OpenID方案中已知的漏洞,并且保护用户的隐私以及整个交互过程中的数据安全。

关键词: 三方密钥协议, 指定验证者的签名, 跨域身份认证

Abstract:

Cloud computing allows users to more easily access to a variety of resources,while it is also a key issue in the cloud computing security field that the identity authentication technology of user access to cloud services. In view of cross domain authentication,the use of OpenID is vulnerable to phishing attacks, replay attacks and other vulnerabilities, the paper mainly proposed a scheme of cross-domain authentication, which based on the ID-based three-party authenticated key agreement protocol and based on the ID-based strong designated verifier signature system to solve the known vulnerabilities in the OpenID, meanwhile protect users’ privacy and strengthen data security in the entire alternating process.

Key words: three-party key agreement, strong designated verifier signature, cross-domain authentication

中图分类号: