计算机集成制造系统 ›› 2014, Vol. 20 ›› Issue (08): 2050-2059.DOI: 10.13196/j.cims.2014.08.raoyu.2050.10.20140827

• 产品创新开发技术 • 上一篇    下一篇

基于票据的虚拟企业跨异构域认证及密钥协商

饶宇1,2,张文芳1,2+,王小敏1   

  1. 1.西南交通大学信息科学与技术学院
    2.西南交通大学信息安全与国家计算网格四川省重点实验室
  • 出版日期:2014-08-31 发布日期:2014-08-31
  • 基金资助:
    国家自然科学基金资助项目(61003245,60903202,61371098);铁道部重大资助项目(2013X012-A-1,2013X012-A-2,2014X008-A);四川省杰出青年学术带头人培育计划资助项目(2011JQ0027);中央高校基本科研业务费资助项目(SWJTU12CX099,SWJTU11CX041)。

Heterogeneous cross-domain authenticated key agreement protocol based on access authorization tickets in virtual enterprises

  • Online:2014-08-31 Published:2014-08-31
  • Supported by:
    Project supported by the National Natural Science Foundation,China(No.61003245,60903202,61371098),the Ministry of Railways Major Projects,China(No.2013X012-A-1,2013X012-A-2,2014X008-A),the Outstanding Youth Foundation of Sichuan Province,China(No.2011JQ0027),and the Fundamental Research Funds for the Central Universities,China(No.SWJTU12CX099,SWJTU11CX041).

摘要: 为了满足虚拟企业资源在异构域间的安全有效共享,提出一个基于访问授权票据的跨异构域认证及密钥协商方案。利用基于公钥认证机制的分布式信任模型,在公钥基础设施域的认证中心证书授权与Kerberos域的认证服务器之间建立起第一级信任关系|在此基础上,由认证中心(或认证服务器联合票据授予服务器)生成并分发外域用户U访问本域资源S的授权票据,并通过设计基于对称密钥密码体制的双向跨域认证及密钥协商协议,建立U与S之间的第二级信任关系,协议的安全性通过SVO逻辑得到证明。分析表明,在满足各级安全需求的前提下,所提方法有效降低了终端计算量与通信量,可完全避免Kerberos域终端的公钥加解密运算,在虚拟企业跨异构域身份认证过程中具有良好的可实施性。

关键词: 虚拟企业, 异构域, 认证密钥协商, 访问授权票据

Abstract: To satisfy the safe and effective sharing of virtual enterprises in heterogeneous domain,a heterogeneous cross-domain authenticated key agreement scheme based on access authorization tickets was proposed.The first-tier trust relationship between Certificate Authority (CA) in PKI domain and Authentication Server (AS) in Kerberos domain by using public key crypto system-based distributed trust model was established.On this basis,the access authorization tickets generated by CA (or AS together with ticket granting service) was distributed to external domain U to access internal domain S,and the second-tier trust relationship between U and S was built by designing two-way cross-domain authenticated key agreement protocol based on symmetry-key system.The security of the new scheme was proved by SVO logic.The analysis showed that the public key cryptographic operations could be entirely avoided for the end users or resources in Kerberos domains,which had better implementation in heterogeneous cross-domain identity authentication process.

Key words: virtual enterprise, heterogeneous domain, authenticated key agreement, access authorization ticket

中图分类号: