引用本文:周彦伟,杨波,王鑫.基于模糊身份的直接匿名漫游认证协议.软件学报,2018,29(12):3820-3836
【打印本页】   【下载PDF全文】   查看/发表评论  【EndNote】   【RefMan】   【BibTex】
←前一篇|后一篇→ 过刊浏览    高级检索
本文已被:浏览 2535次   下载 4663 本文二维码信息
码上扫一扫!
分享到: 微信 更多
基于模糊身份的直接匿名漫游认证协议
周彦伟1,2,3, 杨波1,2,3, 王鑫1,4,3
1.陕西师范大学 计算机科学学院, 陕西 西安 710062;2.密码科学技术国家重点实验室, 北京 100878;3.信息安全国家重点实验室(中国科学院 信息工程研究所), 北京 100093;4.陕西科技大学 电气与信息工程学院, 陕西 西安 710021
摘要:
近年来,为保护用户的隐私安全性,大量适用于全球移动网络环境的匿名漫游认证协议相继被提出.其中,部分协议采用临时身份代替真实身份的方法实现漫游过程中用户身份的匿名性需求,然而临时身份的重复使用,在一定程度上增加了用户的存储负担;部分协议采用身份更新的方法实现临时身份的一次一变性,但是相关信息的存储及更新操作,导致协议的执行效率较低.针对上述不足,提出模糊的直接匿名漫游认证协议.无需家乡代理的协助,通过1轮消息交互,外部代理即可直接完成对移动用户的身份合法性验证.同时,无需更新操作,即可实现漫游过程中临时身份的一次一变性.该机制在实现身份合法性匿名认证的同时,提高了协议的存储和执行效率,并且降低了通信时延.安全性证明表明,该协议在Canetti-Krawczyk(CK)安全模型下可证明是安全的.相较于传统漫游认证协议而言,该协议在存储、通信和计算等方面具有更优的性能,更适用于全球移动网络.
关键词:  全球移动网络  模糊直接认证  模糊提取器  CK安全模型
DOI:10.13328/j.cnki.jos.005302
分类号:
基金项目:国家重点研发计划(2017YFB0802000);国家自然科学基金(61802242,61572303,61772326,61802241,61702259);陕西省自然科学基础研究计划(2018JQ6088,2017JQ6029);"十三五"国家密码发展基金(MMJJ20180217);信息安全国家重点实验室(中国科学院信息工程研究所)开放课题(2017-MS-03);中央高校基本科研业务费专项资金(GK201803064)
Direct Anonymous Authentication Protocol for Roaming Services Based on Fuzzy Identity
ZHOU Yan-Wei1,2,3, YANG Bo1,2,3, WANG Xin1,4,3
1.School of Computer Science, Shaanxi Normal University, Xi'an 710062, China;2.State Key Laboratory of Cryptology, Beijing 100878, China;3.State Key Laboratory of Information Security(Institute of Information Engineering, The Chinese Academy of Sciences), Beijing 100093, China;4.College of Electrical & Information Engineering, Shaanxi University of Science and Technology, Xi'an 710021, China
Abstract:
To provide secure roaming services for mobile users in global mobility networks, many anonymous authentication protocols have been proposed in recent years. But most of them focus only on authentication and fail to satisfy many practical security requirements. In order to achieve anonymity, the traditional anonymous roaming protocols depend on a temporary identity instead of real identity. However, these schemes have storage, communication and computing overheads due to the update operations. To overcome the shortcomings mentioned above, this paper proposes a fuzzy direct anonymous roaming mechanism for global mobility networks, in which the roaming users can fulfill the legitimacy authentication of their identity through one round message exchange with FA. This mechanism not only achieves the legitimate authentication of anonymous identity through fuzzy identity, but also avoids the update operations to get the property of "one at a time" of temporary identity in the process of roaming. Additionally, a security proof shows that this mechanism is provably secure in the CK security model. Moreover, comparative analysis shows that the presented proposal has stronger security, achieves stronger anonymity, and has lower storage, communication and computing overheads. Compared with the traditional anonymous roaming mechanism, the mechanism proposed in this paper is more suitable for the global mobility networks.
Key words:  global mobility network  fuzzy direct authentication  fuzzy extractor  CK security model

引用本文:
【打印本页】   【下载PDF全文】   查看/发表评论  【EndNote】   【RefMan】   【BibTex】
←前一篇|后一篇→ 过刊浏览    高级检索
本文已被:浏览次   下载  
分享到: 微信 更多
摘要:
关键词:  
DOI:
分类号:
基金项目:
Abstract:
Key words: