基于模糊身份的直接匿名漫游认证协议
作者:
作者单位:

作者简介:

周彦伟(1986-),男,甘肃通渭人,工程师,主要研究领域为密码学,匿名通信技术,可信计算;杨波(1963-),男,博士,教授,博士生导师,主要研究领域为密码学,信息安全;王鑫(1979-),女,博士,讲师,主要研究领域为密码学及其应用.

通讯作者:

杨波,E-mail:byang@snnu.edu.cn

中图分类号:

基金项目:

国家重点研发计划(2017YFB0802000);国家自然科学基金(61802242,61572303,61772326,61802241,61702259);陕西省自然科学基础研究计划(2018JQ6088,2017JQ6029);"十三五"国家密码发展基金(MMJJ20180217);信息安全国家重点实验室(中国科学院信息工程研究所)开放课题(2017-MS-03);中央高校基本科研业务费专项资金(GK201803064)


Direct Anonymous Authentication Protocol for Roaming Services Based on Fuzzy Identity
Author:
Affiliation:

Fund Project:

National Key R&D Program of China (2017YFB0802000); National Natural Science Foundation of China(61802242, 61572303, 61772326, 61802241, 61702259); Natural Science Basic Research Plan in Shaanxi Province of China(2018JQ6088, 2017JQ6029); National Cryptography Development Foundation during the 13th Five-year Plan Period (MMJJ20180217);Foundation of State Key Laboratory of Information Security (2017-MS-03); Fundamental Research Funds for the Central Universities(GK201803064)

  • 摘要
  • |
  • 图/表
  • |
  • 访问统计
  • |
  • 参考文献
  • |
  • 相似文献
  • |
  • 引证文献
  • |
  • 资源附件
  • |
  • 文章评论
    摘要:

    近年来,为保护用户的隐私安全性,大量适用于全球移动网络环境的匿名漫游认证协议相继被提出.其中,部分协议采用临时身份代替真实身份的方法实现漫游过程中用户身份的匿名性需求,然而临时身份的重复使用,在一定程度上增加了用户的存储负担;部分协议采用身份更新的方法实现临时身份的一次一变性,但是相关信息的存储及更新操作,导致协议的执行效率较低.针对上述不足,提出模糊的直接匿名漫游认证协议.无需家乡代理的协助,通过1轮消息交互,外部代理即可直接完成对移动用户的身份合法性验证.同时,无需更新操作,即可实现漫游过程中临时身份的一次一变性.该机制在实现身份合法性匿名认证的同时,提高了协议的存储和执行效率,并且降低了通信时延.安全性证明表明,该协议在Canetti-Krawczyk(CK)安全模型下可证明是安全的.相较于传统漫游认证协议而言,该协议在存储、通信和计算等方面具有更优的性能,更适用于全球移动网络.

    Abstract:

    To provide secure roaming services for mobile users in global mobility networks, many anonymous authentication protocols have been proposed in recent years. But most of them focus only on authentication and fail to satisfy many practical security requirements. In order to achieve anonymity, the traditional anonymous roaming protocols depend on a temporary identity instead of real identity. However, these schemes have storage, communication and computing overheads due to the update operations. To overcome the shortcomings mentioned above, this paper proposes a fuzzy direct anonymous roaming mechanism for global mobility networks, in which the roaming users can fulfill the legitimacy authentication of their identity through one round message exchange with FA. This mechanism not only achieves the legitimate authentication of anonymous identity through fuzzy identity, but also avoids the update operations to get the property of "one at a time" of temporary identity in the process of roaming. Additionally, a security proof shows that this mechanism is provably secure in the CK security model. Moreover, comparative analysis shows that the presented proposal has stronger security, achieves stronger anonymity, and has lower storage, communication and computing overheads. Compared with the traditional anonymous roaming mechanism, the mechanism proposed in this paper is more suitable for the global mobility networks.

    参考文献
    相似文献
    引证文献
引用本文

周彦伟,杨波,王鑫.基于模糊身份的直接匿名漫游认证协议.软件学报,2018,29(12):3820-3836

复制
分享
文章指标
  • 点击次数:
  • 下载次数:
  • HTML阅读次数:
  • 引用次数:
历史
  • 收稿日期:2016-06-17
  • 最后修改日期:2016-11-17
  • 录用日期:
  • 在线发布日期: 2018-12-05
  • 出版日期:
您是第位访问者
版权所有:中国科学院软件研究所 京ICP备05046678号-3
地址:北京市海淀区中关村南四街4号,邮政编码:100190
电话:010-62562563 传真:010-62562533 Email:jos@iscas.ac.cn
技术支持:北京勤云科技发展有限公司

京公网安备 11040202500063号