《计算机应用》唯一官方网站

• •    下一篇

基于身份代理重加密的跨链身份管理方案

张鑫1,张金全2,刘德渊3,万武南4,张仕斌5,秦智6   

  1. 1. 成都信息工程大学网络空间安全学院
    2. 成都信息工程学院(航空港)
    3. 成都信息工程大学 网络空间安全学院
    4. 成都信息工程学院 信息安全工程学院,成都 610225
    5. 成都信息工程学院
    6. 成都信息工程大学
  • 收稿日期:2023-12-29 修回日期:2024-02-15 发布日期:2024-03-11 出版日期:2024-03-11
  • 通讯作者: 张金全
  • 基金资助:
    国家重点研发计划“网络空间安全治理”重点专项课题;成都市科技局重点研发支撑计划;成都市科技局重点研发支撑计划;四川省科技计划项目;四川省科技计划项目

Cross-chain identity management scheme based on identity-based proxy re-encryption

  • Received:2023-12-29 Revised:2024-02-15 Online:2024-03-11 Published:2024-03-11
  • Contact: Jin-Quan ZHANG

摘要: 针对目前跨链身份管理中存在的认证效率低,安全性能不足和可扩展性差的问题,提出一种基于身份代理重加密的跨链身份管理方案。首先结合分布式数字身份(DID)构建身份链,为用户提供分布式数字身份标识作为跨链身份标识以及可验证凭证作为访问凭证构建基于凭证信息的访问控制策略;其次,中继链结合密码累加器实现用户身份认证;最后,通过结合基于身份的代理重加密(IBPRE)和签名算法,构建基于身份代理重加密的跨链通信模型。实验分析和评估表明该方案在认证耗时方面相较于RSA和椭圆曲线加密算法(ECC)分别减少了66.9%和4.8%。中继链和身份链实现身份管理,提升去中心化程度和扩展性,构建跨链通信模型和基于凭证信息的访问策略,保障跨链身份管理中的安全性。

关键词: 跨链, 身份管理, 分布式数字身份, 身份代理重加密, 密码累加器

Abstract: In view of the current problems of low authentication efficiency, insufficient security performance and poor scalability in cross-chain identity management, a cross-chain identity management scheme based on identity-based proxy re-encryption was proposed. Firstly, an identity chain was built based on Decentralized IDentifier (DID), which provides users with distributed digital identity as a cross-chain identity and verifiable credentials as access credentials to build an access control strategy based on credential information. Secondly, the relay chain combined the cryptographic accumulator to achieved user identity authentication. Finally, by combined identity-based proxy re-encryption (IBPRE) and signature algorithms, a cross-chain communication model based on identity proxy re-encryption was constructed. Experiment analysis and evaluation show that compared with RSA (Rivest-Shamir-Adleman) and Elliptic Curve Cryptosystem (ECC), the authentication time is reduced by 66.9% and 4.8% respectively. The relay chain and identity chain realize identity management, improve decentralization and scalability, build cross-chain communication models and access policies based on credential information, and ensure security in cross-chain identity management.

Key words: cross-chain, identity management, Decentralized IDentifier(DID), Identity-Based Proxy Re-Encryption(IBPRE), cryptographic accumulator

中图分类号: