| 摘要: |
| 针对数据跨域传输中面临的用户隐私安全与传输数据安全问题, 以及跨域通信系统要求的用户便携性与节点轻量化等实用性问题, 分析现有方案, 提出强对抗环境下面向轻量级节点的数据跨域安全传输方案, 实现: 1)去中心化公钥与身份认证; 2)用户便携式系统访问; 3)通信节点可信密钥协商; 4)抗密钥泄露的数据跨域传输. 形式化证明所提方案的安全性, 并进行原型系统实现与性能评估, 实验结果表明系统计算开销与通信开销是高效的. |
| 关键词: 跨信任域 双向身份认证 数据传输 抗密钥泄露 区块链 |
| DOI:10.13328/j.cnki.jos.007624 |
| 分类号:TP393 |
| 基金项目:国家重点研发计划(2023YFB3106503); 国家自然科学基金面上项目(62472074); 第八届中国科协青年人才托举工程(2022QNRC001); 四川省重大科技专项(2022ZDZX0038); 四川省自然科学基金(24NSFSC2271) |
|
| Secure Cross-domain Data Transmission Scheme for Lightweight Nodes |
|
LU Jing-Wen1, SONG Ya-Qing1, ZHANG Yuan1, HE Xin-Yu1, GONG Jing2, LI Hong-Wei1
|
|
1.School of Computer Science and Engineering (School of Cyber Security), University of Electronic Science and Technology of China, Chengdu 611731, China;2.Sichuan Provincial Big Data Technology Services Center, Chengdu 610041, China
|
| Abstract: |
| To address critical challenges in user privacy and transmission data security in cross-domain environments, as well as practical requirements for user portability and lightweight nodes in cross-domain communication system, this study proposes a blockchain-based secure cross-domain data transmission scheme under highly adversarial conditions. The scheme achieves: 1) decentralized public key management and identity authentication; 2) portable system access for users; 3) trusted key negotiation among communication nodes; 4) key-leakage resistant cross-domain data transmission. The security of the proposed scheme is formally analyzed and proven. Furthermore, a system prototype is implemented to evaluate performance. Experimental results indicate that computation, storage, and communication overheads are all efficiently managed, demonstrating the scheme’s practicality and scalability. |
| Key words: cross trust domain mutual identity authentication data transmission key-leakage resistance blockchain |