| 摘要: |
| 密码工作流(cryptographic workflow)是多用户环境下一种特殊的密码系统工作模式,在这种工作模式下,加密消息需要依据某种策略进行,因此只有履行这一策略的实体才能进行消息解密.为保证在密码工作流模式下密钥封装能够同时实现密钥免托管性和密钥封装传递的不可伪造性,基于签密的思想定义了一个新的密码工作流模式下的密钥封装机制.首先定义了密码工作流模式下基于签密的密钥封装一般模型,并给出了相应的安全模型;其次,结合秘密共享方案、基于身份加密方案和签密方案,提出一个新的结构方案,并在标准模型(standard model)下利用序列游戏证明方法对该结构方案的安全性进行了详细证明.证明结果表明,该密钥封装结构方案能够达到密码工作流模式下要求的接收者安全和外部安全. |
| 关键词: 签密 密钥封装 密码工作流 基于身份加密 秘密共享 接收者安全 外部安全 |
| DOI: |
| 分类号: |
| 基金项目:Supported by the Key Laboratory of National Defense Science and Technology Fund of China under Grant No.51436050404QT2202 (国防科技重点实验室基金) |
|
| Cryptographic Workflow Key Encapsulation Mechanism Based on Signcryption |
|
LAI Xin,HE Da-Ke
|
| Abstract: |
| Cryptographic workflow is a special cryptography system working model in multi-user situations, in which a message is encrypted according to some policy so that only entities guided by the policy are able to decrpt the message. To realize the unforgeability of key encapsulation in without escrow cryptographic workflow, a new key encapsulation mechanism supporting cryptographic workflow based on signcryption is defined. Firstly, a generic model of key encapsulation supporting cryptographic workflow is defined. The corresponding security model of the generic model is also given. Following the generic model, a construction scheme for key encapsulation mechanism supporting cryptographic workflow is proposed by combining secret sharing scheme, ID-based encryption scheme and signcryption scheme. The security of the proposed scheme is proved in standard model with sequences of game. The proposed scheme can satisfy the receiver security and the external security characters in cryptographic work. |
| Key words: signcrytpion key encapsulation cryptographic workflow identity-based encryption secret sharing receiver security external security |