计算机应用

• 人工智能与仿真 •    下一篇

CTCIS2017-202 基于区块链技术的高效跨域认证方案

周致成,李立新,李作辉   

  1. 信息工程大学
  • 收稿日期:2017-09-07 修回日期:2017-09-12 发布日期:2017-09-12 出版日期:2017-09-19
  • 通讯作者: 周致成

Efficient cross domain authentication scheme based on blockchain technology

  • Received:2017-09-07 Revised:2017-09-12 Online:2017-09-12 Published:2017-09-19
  • Contact: Zhi-Cheng ZHOU

摘要: 为解决现有公钥基础设施(PKI)跨域认证方案的效率问题,利用具有分布式多中心、集体维护和不易篡改优点的区块链技术,提出基于区块链技术的高效跨域认证方案,设计了区块链证书授权中心(CA)信任模型、系统架构,给出了区块链证书格式,描述了用户跨域认证协议,并进行了安全性和效率分析。结果表明,在安全性方面,该方案具有双向实体认证等安全属性;在效率方面,与已有跨域认证方案相比,利用区块链不可篡改机制,使用哈希算法验证证书,能减少公钥算法签名与验证的次数、提升跨域认证效率。

关键词: 跨域认证, 区块链, 公钥基础设施, 数字证书, 数字签名

Abstract: To solve the efficiency problem of the existing public key infrastructure (PKI) cross-domain authentication scheme, by using of the advantages of Blockchain technology such as distributed multi-center, collective maintenance and the feature of not easy to tamper, the effective cross-domain authentication scheme was proposed, the Blockchain CA trust model and system architecture was designed, the Blockchain certificate format was provided, the user cross-domain authentication protocol was described, and the security and efficiency was analyzed. The results show that in terms of security, the scheme has mutual entity authentication security attributes; in terms of efficiency, compared with the existing cross domain authentication scheme, this scheme takes advantage of the Blockchain mechanism of not easy to tamper, using the hash algorithm to reduce the number of signature and verification by using public key algorithm to verify certificates, which enhance the efficiency of cross domain authentication.

Key words: cross domain authentication, blockchain, Public Key Infrastructure (PKI) , digital certificate, digital signature

中图分类号: