系统工程与电子技术 ›› 2019, Vol. 41 ›› Issue (2): 438-443.doi: 10.3969/j.issn.1001-506X.2019.02.29

• 通信与网络 • 上一篇    下一篇

基于信任的服务实体跨域认证方案

高阳, 马文平, 刘小雪   

  1. 西安电子科技大学综合业务网理论及关键技术国家重点实验室, 陕西 西安 710071
  • 出版日期:2019-01-25 发布日期:2019-01-25

Cross-domain authentication scheme based on trust for service entity

GAO Yang, MA Wenping, LIU Xiaoxue   

  1. School Key Lab of Integrated Sevices Networks, Xidian University, Xi’an 710071, China
  • Online:2019-01-25 Published:2019-01-25

摘要: 根据目前基于身份的跨域认证过程中域代理(domain agent,DA)数量有限的特点,针对该跨域认证过程中计算复杂的问题,采用信任和基于身份密码体制相结合的方式,提出了基于信任的用户跨域访问信息服务实体(information services entity,ISE)资源的算法。该算法首先完成用户在DA的身份认证,然后采用提出的信任度判断方法进行信任度的判断达到双向认证的目的,最终实现用户跨域访问ISE。仿真结果表明,信任度的判断方法有效地实现抵抗“恶意”DA的攻击,同时该基于信任的ISE跨域认证方案与基于身份的跨域认证方案相比,计算量减少,通信开销降低。

Abstract: According to the characteristics of limited number of domain agents and to solve the complex computational problems in the current crossdomain authentication process based on identity, an algorithm based on trust for users to crossdomain access information services entity (ISE) resources is proposed. The algorithm adopts a combination of trust and identitybased cryptosystems. The algorithm firstly completes the identity authentication of users in the domain agent, and then judges the trust degree by using the proposed trust judgment method to achieve the purpose of bidirectional authentication, and finally realizes user crossdomain access ISE. The simulation results show that the method of judging trust effectively resists attacks from “malicious” domain agents. Compared with identitybased crossdomain authentication, the scheme based on trust for ISE reduces the amount of calculation and communication cost.

中图分类号: