计算机工程与应用 ›› 2012, Vol. 48 ›› Issue (27): 99-104.

• 网络、通信、安全 • 上一篇    下一篇

无碰撞CPK的种子库构建和选取方案

马芯宇1,龙  翔1,范修斌2   

  1. 1.北京航空航天大学 计算机科学与工程学院,北京 100191
    2.中国科学院 软件研究所,北京 100190
  • 出版日期:2012-09-21 发布日期:2012-09-24

Construction and selection scheme of seeded-key database of collision-free CPK

MA Xinyu1, LONG Xiang1, FAN Xiubin2   

  1. 1.School of Computer Science and Engineering, Beihang University, Beijing 100191, China
    2.Institute of Software, Chinese Academy of Sciences, Beijing 100190, China
  • Online:2012-09-21 Published:2012-09-24

摘要: 组合公钥CPK(Combined Public Key)是我国拥有完全知识产权的认证技术,与PKI和IBC相比有其独特的优势。但由于密钥由种子密钥经过组合运算生成,因此可能发生碰撞,有效解决碰撞问题已成为CPK体制发展和完善的关键。介绍了CPK的发展、研究现状和存在问题;根据其构建特点,提出了两种新的种子公/私钥组合选取方法,使得在相同规模的安全需求下,所需种子公/私钥量大大减少;针对产生碰撞的两种可能因素提出了解决方案:用分组密码对用户标识进行映射、按照特定规则产生种子公/私钥库以及对椭圆曲线参数进行约束,从根本上消除了碰撞。优化后的CPK体制,无碰撞,种子库规模小,构建效率高,占用空间少,安全性高,可靠性强,便于管理。

关键词: 密钥管理, 组合公钥(CPK), 种子公/私钥, 标识密钥, 碰撞

Abstract: Combined Public Key(CPK) is an authentication technique which is an independent intellectual property of China. Compared with PKI and IBC, CPK has its particular advantages. However, since the secret key is generated by combining several seeded secret keys, collisions might happen. How to avoid collisions efficiently becomes the linchpin of the development of CPK. After the development and problems of CPK are introduced, two novel methods are put forward to select and combine the seeded public/private keys, which reduces the seeds space evidently with the same level of security. A solution is proposed aiming at two factors which lead to collisions:using block ciphers to map the user identity, produce seeds in accordance with specific rules and restrict the parameters of elliptic curve. The improved CPK system can provide a collision-free key space with a smaller space of seeds, high efficiency, high security, and easy management.

Key words: key management, Combined Public Key(CPK), seeded public/secret key, identity-key, collision