引用本文:施荣华.基于数字签名的安全认证存取控制方案.软件学报,2002,13(5):1003-1008
【打印本页】   【下载PDF全文】   查看/发表评论  【EndNote】   【RefMan】   【BibTex】
←前一篇|后一篇→ 过刊浏览    高级检索
本文已被:浏览 4211次   下载 6321 本文二维码信息
码上扫一扫!
分享到: 微信 更多
基于数字签名的安全认证存取控制方案
施荣华1
中南大学,计算机科学与技术系,湖南,长沙,410075
摘要:
基于Harn数字签名方案和零知识证明,针对信息保护系统构造了一种认证存取控制方案.该方案与已有的存取控制方案相比要更加安全.因为在该方案中,用户与系统不必暴露秘密信息就可以进行双向认证,并且其共享密钥可用于认证用户访问保密文件的请求合法权限.该方案能够在动态环境中执行像改变存取权限和插入/删除用户或文件这样的存取操作,而不影响任何用户的保密密钥.
关键词:  数字签名  零知识证明  安全认证  存取控制  信息保密系统
DOI:
分类号:
基金项目:国家自然科学基金资助项目(60173041)
A Secure Authentication Access Control Scheme Based on Digital Signature
SHI Rong-hua
Abstract:
Based on Harn抯 digital signature scheme and zero-knowledge proof, an authentication access control scheme for information protection system is presented in this paper. The scheme is safer than previously proposed one. In the scheme, two-way authentication may be done between a user and the system without exposing their secret information, and their sharing secret is used for authenticating the requesting user not to illegitimatimately access the protected file. The scheme can perform the access operation in dynamic environments,such as change access privileges and insert/delete users or files without implicating any user's secretkey.
Key words:  digital signature  zero-knowledge proof  secure authentication  access control  information protection system