计算机工程与应用 ›› 2011, Vol. 47 ›› Issue (6): 82-85.

• 网络、通信、安全 • 上一篇    下一篇

普适环境下的一种跨域认证机制

姚 琳1,2,范庆娜2,孔祥维1   

  1. 1.大连理工大学 电信学院,辽宁 大连 116023
    2.大连理工大学 软件学院,辽宁 大连 116023
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2011-02-21 发布日期:2011-02-21

Inter-domain authentication scheme for Pervasive Computing Environments

YAO Lin1,2,FAN Qingna2,KONG Xiangwei1   

  1. 1.Department of Electronic & Information,Dalian University of Technology,Dalian,Liaoning 116023,China
    2.Department of Software,Dalian University of Technology,Dalian,Liaoning 116023,China
  • Received:1900-01-01 Revised:1900-01-01 Online:2011-02-21 Published:2011-02-21

摘要: 由于普适计算的高度移动性,通信的双方经常位于不同的区域,为了保证服务的合法访问以及消息的安全传输,需要进行跨域认证以及安全会话密钥建立。提出了一种新的跨域认证与密钥建立协议,该协议采用生物加密技术省去了证书管理的负担,合理设计了通信双方及其各自服务器之间的交互,完成了跨域双向认证,并采用签密技术为通信双方派生密钥。对协议进行了安全及性能的分析,并用经典的SVO逻辑证明了其正确性。

关键词: 跨域认证, 密钥建立, 生物加密, 签密, 普适计算环境

Abstract: As a result of the high mobility of the pervasive computing,the principles communicating with each other usually locate at different domains.To secure the service access and communications,the principles should authenticate each other and establish a fresh session key.A novel inter-domain authentication and key establishment protocol are proposed.The proposed protocol reduces the burden of certificates management by adopting the biometric encryption.After inter-domain mutual authentication,the two principles build a new session key using the signcryption technique.The protocol can defend lots of attacks and its correctness is proven by the SVO logic.

Key words: inter-domain authentication, key establishment, biometric encryption, signcryption, Pervasive Computing Environments(PCE)